CVE-2025-21396
Published: 29 January 2025
Description
Missing authorization in Microsoft Account allows an unauthorized attacker to elevate privileges over a network.
Security Summary
CVE-2025-21396 is a missing authorization vulnerability (CWE-862) affecting Microsoft Account. Published on 2025-01-29, it enables an unauthorized attacker to elevate privileges over a network. The vulnerability carries a CVSS v3.1 base score of 8.2 (AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:H), reflecting high severity from its network reachability, low complexity, lack of required privileges or user interaction, and impacts on integrity (low) and availability (high).
An unauthenticated attacker (PR:N) can exploit this flaw remotely over the network (AV:N) with low complexity and no user interaction. Exploitation allows privilege elevation within Microsoft Account, potentially disrupting service availability at a high level while causing low-level integrity violations, such as unauthorized modifications.
The official Microsoft Security Response Center advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21396 provides details on mitigation, including any available patches or workarounds.
Details
- CWE(s)