Impact
This SQL injection flaw arises from improper neutralization of special elements in an SQL command used by Microsoft Entra Connect Sync. Because the component executes unsanitized input, an authorized user can inject arbitrary SQL statements, ultimately allowing local privilege elevation within the Entra Connect installation. The increased privileges could enable the attacker to view or alter identity data and configuration settings, potentially compromising subsequent authentication and authorization processes that rely on Entra Connect.
Affected Systems
The affected product is Microsoft Entra Connect. No specific vulnerable version information is provided. The guidance should be applied to all installations of Entra Connect that have not yet been patched to the latest release.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity risk, while the EPSS score of less than 1% suggests a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog, implying that no confirmed widespread exploitation has been reported yet. Based on the nature of the flaw (CWE-89) and the fact that Entra Connect typically runs with administrative privileges on the host, the likely attack vector is via local or remote access to the management interface that submits data to the vulnerable component.
OpenCVE Enrichment