Azure SDK Spoofing Vulnerability
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.5epss 1.8%
exploitation probability
1.8%top 23% of all CVEs
observed exploitation
nono source reports it
In short
Azure SDK contains a spoofing vulnerability that allows attackers to impersonate legitimate services. This flaw could enable unauthorized access to sensitive data or operations by tricking applications into trusting malicious endpoints.
Technical detail
A validation bypass in Azure SDK fails to properly verify service endpoints, allowing an attacker to redirect client connections to attacker-controlled servers. The vulnerability requires network-level access or DNS manipulation; successful exploitation results in client-side credential exposure and unauthorized API calls.
Summary generated and translated by AI from the official description.
Azure SDK Spoofing Vulnerability
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C
Affected products
Microsoft · Azure SDK