Executive brief
Azure Stack HCI is Microsoft's hyperconverged infrastructure platform used by organizations to run virtualized workloads. An attacker on the network can exploit a response discrepancy to infer sensitive information about the system, potentially revealing details that could be used in follow-up attacks.
Technical details
This vulnerability is classified as an observable response discrepancy, a variant of timing or response-analysis attack. The vulnerability allows an unauthenticated, network-adjacent attacker to extract information by observing differences in how Azure Stack HCI responds to certain requests. The attack requires network access to the affected system but does not require authentication or user interaction. Successful exploitation could enable information disclosure that facilitates reconnaissance or privilege escalation in a subsequent attack phase. Microsoft has released a security update to address this issue.
Affected products
- Microsoft Azure Stack HCI
Timeline
- 2026-08-20: disclosed