CVE Feed

    Dashboard / CVE / CVE-2021-42306

    CVE-2021-42306

    An information disclosure vulnerability manifests when a user or an application uploads unprotected private key data as part of an authentication certificate keyCredential  on an Azure AD Application or Service Principal (which is not recommended). This vulnerability allows a user or service in the tenant with application read access to read the private key data that was added to the application. Azure AD addressed this vulnerability by preventing disclosure of any private key values added to the application. Microsoft has identified services that could manifest this vulnerability, and steps that customers should take to be protected. Refer to the FAQ section for more information. For more details on this issue, please refer to the MSRC Blog Entry.

    Published:Nov 24, 2021
    Last Modified:Aug 19, 2026
    EPS:Nov 24, 2021
    EPSS Score:0.03082
    CVSS Score:8.1

    Affected Products

    Vendor
    Microsoft
    Product
    Azure Active Directory
    Vendor
    Microsoft
    Product
    Azure Active Site Recovery
    Vendor
    Microsoft
    Product
    Azure Automation
    Vendor
    Microsoft
    Product
    Azure Migrate

    Exploits

    No exploit reference

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High