Act
active
Microsoft Patches CVSS 10.0 Privilege Escalation in Azure AI Foundry
- Engineer — Plan: No customer-side patch action is needed — Microsoft fixed this server-side — but a public PoC existed before the fix, so audit Azure AI Foundry activity and IAM logs for unauthorized privilege escalations that may have occurred during the exposure window.
- SOC/IR — Act: A public PoC on GitHub combined with a CVSS 10.0 network-accessible privilege escalation means exploitation attempts are plausible; hunt for anomalous privilege escalation events in Azure AI Foundry audit logs and Azure Entra activity logs predating the patch.
- Leader — Plan: Confirm whether Azure AI Foundry is in use and have the team verify no exploitation occurred during the pre-patch window; the CVSS 10.0 score and public PoC will likely generate customer or board inquiries, so prepare a brief noting Microsoft resolved it server-side with no customer action required.
- Signals: CVE-2026-85889 — CISA KEV: not listed, EPSS n/a, public PoC on GitHub
This entry was curated and judged by AI (Claude) with automated enrichment
(CISA KEV / EPSS / public PoC). Verify against the original source before
acting. Found a bad verdict?
Report it —
confirmed errors go to the corrections log.