Azure AI Foundry missing authentication allows unauthorized privilege escalation
Missing authentication for a critical function in Azure AI Foundry lets an unauthenticated attacker escalate privileges over a network. CVSS 10.0 critical; Microsoft patched on the service side with no customer action required.
- Vendor
- Microsoft
- Product
- Azure AI Foundry
- CVSS
- 10.0
- EPSS (exploit probability)
- 0.5%
- Status
- patched
- Published
A missing-authentication condition on a critical function in Azure AI Foundry allowed an unauthenticated attacker to escalate privileges over a network. Microsoft assigned CVSS 10.0 and patched the vulnerability on the service side; no action is required from Azure AI Foundry customers.
Refer to the MSRC advisory for the official disclosure. If your organization runs workloads on Azure AI Foundry, review activity logs for anomalous access from the period before the patch, though Microsoft has not confirmed active exploitation.
