CVE-2023-35625 is an information disclosure vulnerability affecting the Microsoft Azure Machine Learning SDK for Compute Instances. With a CVSS score of 4.7 (Medium), this vulnerability allows a low-privileged attacker with local access and high attack complexity to potentially disclose sensitive information. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or KEV listing. Community discussion and media coverage are minimal, with only one mention and one article referencing it within a broader patch Tuesday summary.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.5.0CPE matchmatch criteria | cpe:2.3:a:microsoft:azure_machine_learning_software_development_kit:*:*:*:*:*:*:*:* | ||
>= 1.0.0, < 1.5.0CPE match | cpe:2.3:a:microsoft:azure_machine_learning:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.