Impact
Improper authorization in Azure Database for PostgreSQL allows an attacker who already has some authorized access to elevate privileges over the network, potentially attaining full control over the database and its data. The weakness is an instance of improper authorization (CWE-285).
Affected Systems
Microsoft Azure HorizonDB, which is Azure Database for PostgreSQL. No specific version information is provided.
Risk and Exploitability
The vulnerability has a CVSS score of 9.9, indicating critical severity. The EPSS score is less than 1 %, suggesting that exploitation is currently unlikely but could change. It is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is remote over a network; an attacker must already be authenticated or have some authorized presence within the environment to take advantage of the improper authorization and increase their privileges.
OpenCVE Enrichment