Impact
The vulnerability is a server‑side request forgery flaw in Azure Virtual Machines that can be exploited by an authorized attacker to gain elevated privileges on the network. The weakness is classified as CWE‑918, indicating that improper validation of user‑supplied URLs allows the attacker to manipulate outbound requests. If successfully exploited, the attacker can bypass normal access controls and execute privileged operations within the virtual machine environment.
Affected Systems
Microsoft Azure Virtual Machines
Risk and Exploitability
The CVSS score of 8.5 indicates a high severity impact. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, suggesting no known widespread exploitation yet. The likely attack vector is an SSRF that requires authorized access to the virtual machine; the attacker must have some level of authenticated control to craft the malicious request.
OpenCVE Enrichment