Impact
The vulnerability arises from improper access control (CWE‑284) within Microsoft Purview eDiscovery, enabling an authorized user to elevate their privileges over the network. An attacker who already has authorized access can exploit this flaw to gain higher level rights, potentially allowing them to access restricted data or manipulate the system. The flaw does not directly expose data or services, but it provides a path to broaden an attacker’s capabilities within the Purview environment.
Affected Systems
Microsoft Purview eDiscovery is affected by this vulnerability. No specific version information is provided, so all deployments of Purview eDiscovery potentially carry the risk until a patch is applied.
Risk and Exploitability
The CVSS score of 8.8 indicates high severity, while the EPSS score is not available and it is not listed in CISA's KEV catalog. The likely attack vector requires an authenticated user over the network, as the description notes an authorized attacker can elevate privileges. Exploitation would involve leveraging existing legitimate access rights and bypassing internal controls to assume higher privileges, which could compromise data confidentiality and integrity. The lack of a public exploitation indicator suggests that, although the risk is high, out‑of‑band exploitation has not yet been observed.
OpenCVE Enrichment