Impact
This vulnerability exists in Microsoft Azure Active Directory B2C where an authorization bypass allows an attacker to tamper with a user-controlled key to elevate privileges. The flaw is rooted in improper validation of the key, enabling a non‑privileged user to gain higher rights and potentially control the tenant or access sensitive data. Because the attacker only needs a crafted key, the impact is a direct privilege elevation that compromises confidentiality, integrity, and availability of the tenant’s services.
Affected Systems
Microsoft Entra Azure Active Directory B2C is affected. No specific product versions were disclosed, so any deployment of Azure AD B2C that has not applied the latest security updates may be vulnerable.
Risk and Exploitability
The CVSS score of 10 highlights a critical severity. EPSS data is not available, and the vulnerability is not listed in the CISA KEV catalog. While an explicit attack vector is not stated, the likely vector is a remote exploitation of the B2C API using a user‑supplied key, as inferred from the description. No additional prerequisites are mentioned, suggesting that an attacker can exploit the flaw with minimal information beyond the ability to create or modify a key. Given the lack of EPSS data, evaluation relies on CVSS and potential for exploitation, indicating a high risk to affected tenants.
OpenCVE Enrichment