Impact
The vulnerability is a server‑side request forgery (CWE‑918) in Microsoft Entra ID (Azure Active Directory). An attacker who already has authorized credentials can craft requests that cause the Entra ID service to contact internal endpoints, enabling escalation of privileges across the network. The result is that the attacker gains access beyond the original user’s permissions.
Affected Systems
Microsoft Entra ID, also known as Azure Active Directory. No specific patch version information is disclosed; affected installations remain unspecified. Administrators should review Microsoft Entra ID deployments for potential exposure.
Risk and Exploitability
The CVSS score of 9.9 indicates a critical severity, but the EPSS score is unavailable, so exact exploitation probability cannot be assessed. The attack requires an authenticated session and internal network connectivity. Because the flaw can be triggered from a legitimate user context, it bypasses typical credential checks, making it highly damaging if an attacker can manipulate the service. The vulnerability is not listed in the CISA KEV catalog.
OpenCVE Enrichment