Interestana
Home/News/Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw

Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw

Microsoft released security patches on an unspecified date to address a critical vulnerability within its Azure AI Foundry service. This flaw, identified by the Common Vulnerability Scoring System (CVSS) with a perfect score of 10.0, poses a significant risk of unauthorized privilege escalation for affected users. The vulnerability is formally tracked as CVE-2026-85889. According to Microsoft's advisory, the vulnerability stems from a "missing authentication for critical function in Azure AI Foundry." This technical deficiency allows an attacker who is not authenticated to exploit the system and gain elevated privileges. The exploitation can occur "over a network," meaning an attacker does not need direct physical access to the compromised infrastructure. The severity of a CVSS 10.0 score indicates that the vulnerability is exploitable with minimal effort and has a high impact on confidentiality, integrity, and availability. Azure AI Foundry is a platform designed to help developers build, train, and deploy artificial intelligence models. It provides tools and services that integrate with Azure's cloud infrastructure, enabling businesses to leverage AI for various applications. The potential for privilege escalation means that an attacker could gain administrative control over resources or data within the Azure AI Foundry environment that they would not normally have access to. This could lead to data theft, unauthorized modification of AI models, disruption of services, or further compromise of connected systems. Microsoft has stated that "No customer action is required" to remediate this vulnerability, implying that the patches have been applied automatically to the Azure service. This automated patching is a common practice for cloud-based services where the provider manages the underlying infrastructure. However, it is always advisable for customers to verify their security configurations and monitor their Azure environments for any suspicious activity. The disclosure of this high-severity vulnerability underscores the ongoing challenges in securing complex cloud-based AI platforms. As AI services become more integrated into critical business operations, the security of these platforms is paramount. Attackers are increasingly targeting AI infrastructure, recognizing the potential for high-impact breaches. Microsoft's prompt patching of this critical flaw demonstrates its commitment to maintaining the security of its cloud services, but it also highlights the need for continuous vigilance and robust security practices from both providers and users of AI technologies.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next