CVE-2021-42306 is an information disclosure vulnerability in Microsoft Azure Active Directory, Azure Site Recovery, Azure Automation, and Azure Migrate. It allows users or services with application read access to retrieve private key data if it was improperly uploaded as part of an authentication certificate keyCredential. Rated 8.1 HIGH (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N), this vulnerability is remotely exploitable with low complexity, requiring only low privileges to achieve high confidentiality and integrity impact. While Microsoft has addressed the flaw and provided customer guidance, there is no evidence of active exploitation, public exploit code, or significant community discussion beyond initial media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2021-10-30CPE matchmatch criteria | cpe:2.3:a:microsoft:azure_active_directory:*:*:*:*:*:*:*:* | ||
< 2021-11-01CPE matchmatch criteria | cpe:2.3:a:microsoft:azure_active_site_recovery:*:*:*:*:*:*:*:* | ||
< 2021-10-15CPE matchmatch criteria | cpe:2.3:a:microsoft:azure_automation:*:*:*:*:*:*:*:* | ||
< 2021-11-02CPE matchmatch criteria | cpe:2.3:a:microsoft:azure_migrate:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.