Impact
The vulnerability manifests as a missing authorization check within Microsoft Entra ID that permits an attacker who is already authorized to elevate their privileges. This is a classic missing authorization flaw, under CWE-862, which means the system fails to verify that a user has the required permissions before granting elevated capabilities. Executing this flaw would allow the attacker to perform actions normally restricted to higher‑privilege users, potentially compromising confidentiality and integrity across the Entra environment.
Affected Systems
Microsoft Entra ID is the affected product. No specific versions are listed, so all deployments should consider review pending vendor guidance.
Risk and Exploitability
The CVSS score of 9.9 indicates high severity. The EPSS score is not available, and the vulnerability is not listed in CISA KEV. Based on the description, the likely attack vector is internal network or authenticated user exploitation, meaning the attacker must be authenticated to the system. No workaround is provided, so the risk remains until a patch is applied.
OpenCVE Enrichment