Impact
The vulnerability arises from improper authorization handling in Azure Arc, allowing an unauthorized attacker to gain elevated privileges over a network. It is classified as CWE-863 and carries a CVSS score of 10, indicating the potential for full system compromise. If exploited, an attacker could take control of Azure Arc‑managed resources, exfiltrate data, or pivot to other infrastructure components.
Affected Systems
Microsoft Azure Arc is affected. No version details are disclosed in the advisory, so any deployment of Azure Arc that uses the implicated components should be considered at risk. Organizations should inventory their Azure Arc instances and verify whether the vulnerability applies to their environment.
Risk and Exploitability
The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, so the exact exploitation probability is unknown, but the severity remains high. The attack vector is inferred to be network‑based; an attacker must reach the Azure Arc management endpoints. Until a vendor fix is released, this should be treated as a critical issue.
OpenCVE Enrichment