Cyber Posture

CVE-2025-21396

High

Published: 29 January 2025

Published
29 January 2025
Modified
12 February 2025
KEV Added
Patch
CVSS Score 8.2 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H
EPSS Score 0.0205 83.9th percentile
Risk Priority 18 60% EPSS · 20% KEV · 20% CVSS

Description

Missing authorization in Microsoft Account allows an unauthorized attacker to elevate privileges over a network.

Security Summary

CVE-2025-21396 is a missing authorization vulnerability (CWE-862) affecting Microsoft Account. Published on 2025-01-29, it enables an unauthorized attacker to elevate privileges over a network. The vulnerability carries a CVSS v3.1 base score of 8.2 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H), reflecting high severity from its network reachability, low complexity, lack of required privileges or user interaction, and impacts on integrity (low) and availability (high).

An unauthenticated attacker (PR:N) can exploit this flaw remotely over the network (AV:N) with low complexity and no user interaction. Exploitation allows privilege elevation within Microsoft Account, potentially disrupting service availability at a high level while causing low-level integrity violations, such as unauthorized modifications.

The official Microsoft Security Response Center advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21396 provides details on mitigation, including any available patches or workarounds.

Details

CWE(s)
CWE-862

Affected Products

microsoft
account
all versions

References