Impact
An information disclosure vulnerability exists in Microsoft Discovery Studio due to improper neutralization of special elements in data query logic. The flaw allows an attacker who can send crafted query data to the system to exfiltrate sensitive configuration or internal data over the network. This weakness is classified as CWE-943 and can lead to confidentiality loss of secrets or system state.
Affected Systems
The vulnerability affects Microsoft Discovery Studio. No specific product version information is supplied, so all currently deployed instances of this software are potentially impacted until a patch is applied.
Risk and Exploitability
The CVSS base score of 7.4 indicates a high severity risk. The EPSS value is not available, and the vulnerability is not listed in CISA KEV. The attack vector is inferred to be remote over a network, as the disclosure occurs when unauthorized users send data queries. Yielding the attacker the ability to read returned data without authentication or authorization. Consequently, organizations should treat this as a significant risk until mitigated.
OpenCVE Enrichment