CVE-2026-65673Important
Microsoft Entra Connect Elevation of Privilege Vulnerability
Assessment
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Entra Connect Sync allows an authorized attacker to elevate privileges locally.
- Severity
- Important
- CVSS base score
- 7.8CVSS:3.1/
AV:L/ AC:L/ PR:L/ UI:N/ S:U/ C:H/ I:H/ A:H/ E:U/ RL:O/ RC:C - Impact
- Elevation of Privilege
- EPSS, next 30 days
- 0.3%Higher than 22.8% of scored CVEs · FIRST model run 26 Sep 2026 · about EPSS
- Exploitability
- Exploitation Less Likely
- Publicly disclosed
- No
- Customer action
- Required: apply the update
- Component
- Microsoft Entra Connect Sync
- Weakness
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
- Issued by
- Microsoft
- Published
- 11 Aug 2026 · August 2026
- Last revised
- 11 Aug 2026
Updates that fix it
0 KBsNo KB listed
MSRC lists no downloadable update, which usually means a service-side fix or a release-notes update. Check the MSRC advisory.
Affected products
Azure1 affected product
- Microsoft Entra Connect