CVE-2017-8613 describes an Elevation of Privilege vulnerability in Microsoft Azure AD Connect. If misconfigured during enablement, this flaw allows an attacker to reset passwords for arbitrary on-premises Active Directory privileged user accounts, leading to unauthorized access. With a CVSS score of 8.1 (HIGH), this vulnerability is network-exploitable with high impact on confidentiality, integrity, and availability, though it requires high attack complexity. There is no evidence of active exploitation, nor are public exploit codes available, and it has received limited community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.1.524.0CPE matchmatch criteria | cpe:2.3:a:microsoft:azure_active_directory_connect:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.