Impact
The vulnerability lies in a missing authentication check for a critical function in Azure AI Language Authoring. Because the function can be invoked without credentials, an unauthenticated attacker can elevate privileges over the network, enabling unauthorized access or configuration changes. The weakness is classified as CWE‑306 and can compromise the confidentiality and integrity of data handled by the service.
Affected Systems
Microsoft’s Azure AI Language Authoring service is affected. No specific version or release information is provided; any instance of the Azure AI Language Authoring deployment that has not applied the recent Microsoft update may be vulnerable.
Risk and Exploitability
The CVSS score of 10 indicates the highest severity. While an EPSS score is not available, the lack of authentication makes the attack vector trivial for anyone who can reach the service over the network, meaning exploitation is likely but not quantified. Because the vulnerability is not listed in CISA KEV, there is no public evidence of current exploitation, but the risk remains high due to the nature of the flaw.
OpenCVE Enrichment