An authenticated attacker can exploit an Server-Side Request Forgery (SSRF) vulnerability in Microsoft Azure Health Bot to elevate privileges over a network.
The product does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.