Impact
The flaw stems from a permissive cross‑domain policy that permits untrusted domains to interact with the Azure Arc SQL Server Extension. An attacker capable of supplying or controlling input from such an untrusted domain can exploit this weakness to elevate privileges on the target system or over the network, potentially executing arbitrary commands or accessing restricted data. The vulnerability involves unsafe request handling and SQL injection, reflected in CWE‑1390, CWE‑89 and CWE‑942.
Affected Systems
Affected product: Microsoft Azure Arc SQL Server Extension. Version information is not provided; all deployed instances may be susceptible.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability. EPSS data is unavailable and the flaw is not listed in the CISA KEV catalog. The likely attack vector is a network‑based exploit originating from an unauthorized, untrusted domain that leverages the permissive cross‑domain policy. Because the flaw permits privilege escalation, the risk of compromise is significant if the service is exposed to untrusted networks.
OpenCVE Enrichment