Impact
The vulnerability stems from the use of incorrectly‑resolved names or references within Azure Arc, permitting an attacker who is not authorized to elevate privileges over a network. This flaw is classified as an access‑control weakness (CWE‑706). If exploited, an attacker could gain higher-level permissions on Azure services, potentially accessing sensitive data or executing privileged operations.
Affected Systems
The affected product is Microsoft Azure Web Apps with Azure Arc integration. No specific product or version qualifiers are listed in the CNA data.
Risk and Exploitability
The CVSS score of 10 indicates a critical severity, but the EPSS value is unavailable. The vulnerability is not marked in the CISA KEV list. Attacks would likely use remote network access to reach the Azure Arc components; however, no explicit prerequisites are detailed in the advisory, so further information from Microsoft is needed to determine exact attack steps. The lack of a publicly listed exploit means the risk of exploitation remains uncertain, but the severity warrants immediate attention.
OpenCVE Enrichment