Executive brief
Microsoft Azure Orbital Spatio is a cloud-based platform used for processing and analyzing geospatial and satellite data. A critical vulnerability allows an unauthorized person to upload malicious files to the service, which could lead to full control over the system and the theft of sensitive data. This flaw poses a significant risk to operations and data integrity as it requires no user interaction or existing account to exploit.
Technical details
A critical vulnerability (CWE-434) exists in Microsoft Azure Orbital Spatio due to the unrestricted upload of files with dangerous types. An unauthenticated remote attacker can exploit this flaw by sending a specially crafted request to upload a malicious file, such as a script or executable, to the server. Because the application fails to properly validate the file type or content, the attacker can achieve remote code execution (RCE) with high privileges. The vulnerability has a CVSS score of 10.0, reflecting that it is network-reachable, requires no privileges, and has a critical impact on confidentiality, integrity, and availability.
Affected products
- Microsoft Azure Orbital Spatio
Timeline
- 2026-05-22: disclosed
- 2026-05-22: advisory: Microsoft published the security update guide.