Impact
Microsoft Azure CLI contains an improper neutralization of special elements used in a command, allowing a command injection vulnerability. An attacker who has authorized access can supply crafted input that will be executed on the host where the CLI runs, potentially compromising confidentiality, integrity, and availability of that system. The weakness is a classic command injection flaw (CWE-77).
Affected Systems
The vulnerability affects Microsoft Azure CLI. Specific version details are not disclosed in the official advisory, so all versions of Azure CLI may be vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 8.0 indicates a high severity. No EPSS score is available, and the issue is not currently listed in CISA KEV, but the lack of a public exploit does not diminish the risk to an authorized attacker who can send crafted requests over the network. The likely attack vector is through network interfaces or scripts that invoke Azure CLI with unsanitized user input.
OpenCVE Enrichment