Impact
The vulnerability in Microsoft Azure Confidential Ledger exposes a dangerous method or function that, when invoked by an authorized user, allows execution of arbitrary code over a network. This flaw results in full remote code execution, giving an attacker the ability to compromise the integrity and confidentiality of the ledger data and potentially gain system-wide control. The weakness is classified as CWE‑749, which addresses the improper use of dangerous functions that can be abused for malicious purposes.
Affected Systems
The affected product is Microsoft Azure Confidential Ledger. No specific product versions are listed in the advisory, so all deployments of Azure Confidential Ledger may be at risk until a fix is applied.
Risk and Exploitability
The CVSS score of 9.1 indicates a high severity for this RCE in a remote context. The EPSS score is not available, but the lack of listing in the CISA KEV catalog suggests no publicly known widespread exploitation. The likely attack vector is a network-based command sent by an authorized user, meaning that any compromised or malicious principal with accessible credentials could exploit this flaw.
OpenCVE Enrichment