Impact
The vulnerability arises from missing authentication on a critical function in Microsoft Planetary Computer Pro, enabling an unauthorized attacker to elevate privileges over a network. This flaw allows an adversary to gain higher-level access than intended, potentially compromising confidentiality, integrity, and availability of planetary data services. The weakness is classified as CWE-306, indicating missing authentication controls.
Affected Systems
Affected vendors and products include Microsoft’s Planetary Computer Pro, specifically the GeoCatalog component. No version information is provided, so all deployed instances of this product are potentially impacted until a patch is applied.
Risk and Exploitability
The CVSS score of 10 denotes a critical severity, and the EPSS score is not available, but the absence of authentication makes the vulnerability highly exploitable over the network. Attackers could exploit this flaw remotely without needing credentials, making it a high-priority threat. The vulnerability is not yet listed in the CISA KEV catalog; however, its critical nature warrants prompt remediation.
OpenCVE Enrichment