Impact
The vulnerability arises from improper neutralization of argument delimiters in shell commands executed by Microsoft Azure Managed Instance for Apache Cassandra. An attacker can inject arbitrary arguments that are passed directly to the underlying command line, allowing execution of arbitrary code. The resulting remote code execution gives the attacker full control over the instance and its data.
Affected Systems
The affected product is Microsoft Azure Managed Instance for Apache Cassandra. No specific version information is provided in the advisory, so all current releases of this service that have not been patched are potentially vulnerable.
Risk and Exploitability
The CVSS score of 10 indicates the maximum severity of a security flaw. The EPSS score is not available and the flaw is not listed in the CISA KEV catalog. Attackers can exploit the flaw by sending crafted requests over the network to the managed instance; once network access is achieved, the argument injection allows arbitrary commands to run without authentication, making exploitation straightforward.
OpenCVE Enrichment