Impact
The vulnerability is a classic OS command injection flaw located in Azure HDInsight’s Ambari component. An attacker who already has authorized access within the HDInsight environment can inject and execute arbitrary operating‑system commands, granting them elevated administrative privileges over the network. The flaw is a misuse of untrusted input in command construction, as classified by CWE‑78.
Affected Systems
Microsoft Azure HDInsight is the affected product. No specific version numbers are listed in the available information, so any deployment of Azure HDInsight may be impacted until the patch is applied.
Risk and Exploitability
The CVSS score of 7.2 places this issue in the high severity range, and although the EPSS score is not available, the lack of an entry in the CISA KEV catalog suggests that widespread exploitation has not yet been observed. The likely attack vector requires an authenticated user to interact with the Ambari service over the network; no remote anonymous exploitation is described. Given the high score and potential for privilege escalation, the risk to an organization using Azure HDInsight is significant if no mitigation is performed.
OpenCVE Enrichment