Impact
The vulnerability is an improper access control flaw in Azure Logic Apps that permits an unauthorized attacker to elevate privileges across a network. It represents a classic privilege escalation issue, classified under CWE-284, allowing the attacker to gain higher level permissions than intended.
Affected Systems
Microsoft Azure Logic Apps is the affected product. No specific version information is provided, so all deployments of Azure Logic Apps that are not patched are potentially impacted.
Risk and Exploitability
The CVSS score of 10 marks this flaw as critical. The EPSS score of less than 1% indicates a very low probability that exploitation is occurring in the wild, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector is a network-based approach where an attacker has some connectivity to the Logic Apps environment, enabling them to exploit the access control weakness to increase privileges.
OpenCVE Enrichment