Executive brief
Microsoft Azure Virtual Network Gateway, a service used to connect on-premises networks to Azure via VPN, contains a critical vulnerability. An attacker with basic user permissions can execute malicious code across the network, potentially leading to a full takeover of the gateway service. This could result in unauthorized access to private corporate data, interception of network traffic, or a complete disruption of connectivity between office locations and the cloud.
Technical details
A remote code execution vulnerability exists in the Microsoft Azure Virtual Network Gateway due to improper input validation (CWE-20). An attacker authenticated with low-privileged user permissions can exploit this flaw by sending specially crafted network requests to the gateway. Successful exploitation allows for arbitrary code execution with high privileges. Because the vulnerability carries a 'Scope: Changed' (S:C) designation in its CVSS vector, an attacker may be able to impact components beyond the immediate security scope of the gateway itself. Microsoft has addressed this in their cloud service; users of exclusively hosted services typically receive these updates automatically.
Affected products
- Microsoft Azure Virtual Network Gateway
Timeline
- 2026-05-22: disclosed
- 2026-05-22: advisory: MSRC advisory published