Impact
A missing authentication check for a critical function in Azure AI Foundry allows an attacker who can reach the service over the network to gain elevated privileges. This flaw corresponds to the improper authorization weakness designated CWE-306. Because the function is not protected, an unauthenticated user can execute actions normally reserved for privileged accounts, potentially compromising the integrity and availability of the platform and any data processed by it.
Affected Systems
Microsoft Azure AI Foundry is impacted. No specific version information is provided; all deployments of the service are potentially vulnerable until a patch is applied.
Risk and Exploitability
The vulnerability carries a CVSS score of 10, indicating that a successful exploit would provide complete control over the targeted system. The EPSS score of less than 1% suggests a low probability that an attacker has already found a workable exploit at this time, and the issue is not yet listed in CISA's KEV catalog. The likely attack vector is over the network, targeting any host or service that hosts Azure AI Foundry without proper authentication guards. Attackers would need network access to the exposed endpoint; once accessed, privilege escalation can be achieved without additional authentication.
OpenCVE Enrichment