[WID-SEC-2026-2184] Microsoft Azure und Entra: Mehrere Schwachstellen ermöglichen Privilegieneskalation CVSS Base Score 9.9 (kritisch) CVSS Temporal Score 8.6 (hoch) Remoteangriff ja Datum 02.07.2026 Stand 03.07.2026 Mitigation ja Betroffene Systeme Betriebssystem Linux Sonstiges UNIX Windows Produktbeschreibung Azure ist eine Cloud Computing-Plattform von Microsoft. Microsoft Entra ID (früher Azure Active Directory) ist ein cloudbasierter Identitäts- und Zugriffsverwaltungsdienst von Microsoft. Produkte 02.07.2026 Microsoft Azure Synapse Microsoft Azure Open AI Microsoft Entra Provisioning Service Angriff Angriff Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Microsoft Azure und Microsoft Entra ausnutzen, um seine Privilegien zu erhöhen. CVE Informationen Versionshistorie Feedback zum Advisory geben
Multiple critical vulnerabilities in Microsoft Azure and Microsoft Entra allow an authenticated remote attacker to perform privilege escalation. The CVSS Base Score for these vulnerabilities is 9.9 (Critical). Affected products include Microsoft Azure Synapse, Microsoft Azure Open AI, and the Microsoft Entra Provisioning Service. A mitigation is available, but specific patch versions are not detailed in the provided advisory.