Impact
Improper limitation of a pathname to a restricted directory in Azure Arc enables an attacker to exploit path traversal and elevate privileges over a network. The flaw allows the attacker to specify a crafted path that causes the system to resolve files or directories outside the intended scope, resulting in unauthorized privilege escalation. This impact can compromise the security posture of the affected Azure Arc deployment by granting the attacker higher authority than intended.
Affected Systems
Microsoft Azure Arc is affected. No version information is specified in the advisory, so the vulnerability applies to all Azure Arc deployments that have not yet incorporated the vendor’s update.
Risk and Exploitability
The CVSS score of 9.3 signals a high impact for successful exploitation. The EPSS score, reported as less than 1%, indicates that known exploitation activity is currently rare, but the vulnerability remains usable in the future. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attacker must have network connectivity to the Azure Arc service to trigger the path traversal, implying a remote network attack vector.
OpenCVE Enrichment