Microsoft Azure AI Document Intelligence Studio Path Traversal Vulnerability Allowing Privilege Escalation

Vulnerability

A path traversal vulnerability has been identified in Microsoft Azure AI Document Intelligence Studio. This issue allows an unauthorized attacker to bypass authentication and authorization, accessing files located one directory above the intended file upload path. As a result, the attacker could potentially elevate privileges by downloading content from the parent folder of the mounted path.

Impact

Exploitation of this vulnerability could lead to unauthorized access of files, allowing an attacker to download sensitive content and potentially escalate privileges within the application.

Remediation

Users can update to the latest version of Azure AI Document Intelligence Studio to address this vulnerability. The update will not affect user data or settings.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
7.4
remediation
7.7
relevance
0.0
threat
0.1
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.