Impact
The vulnerability permits an unauthorized attacker to capture and replay authentication traffic, effectively bypassing user verification and spoofing requests in Microsoft Authentication Library (MSAL) for Node.js. This flaw allows the attacker to impersonate legitimate clients or users without needing to know secrets, undermining the integrity of the authentication process.
Affected Systems
The affected product is the Microsoft Authentication Library for Node.js. Version information is not specified in the advisory, so all current releases should be reviewed for the presence of this issue until a vendor patch is released.
Risk and Exploitability
The CVSS score of 7.4 indicates high severity, and while the EPSS score is not available, the absence of a KEV listing suggests no current exploit broker awareness. The likely attack vector involves an attacker intercepting network traffic between a client and an authentication server (e.g., over an insecure channel) and replaying the captured authentication payload. Organizations without hardened network or transport security may be particularly vulnerable. Until a vendor fix becomes available, the risk remains elevated and monitoring for replay attempts is advised.
OpenCVE Enrichment