1.1 C
New York
Sunday, February 23, 2025

Microsoft Patches Vital Azure AI Face Service Vulnerability with CVSS 9.9 Rating


Feb 04, 2025The Hacker InformationVulnerability / Cloud Safety

Microsoft Patches Vital Azure AI Face Service Vulnerability with CVSS 9.9 Rating

Microsoft has launched patches to handle two Vital-rated safety flaws impacting Azure AI Face Service and Microsoft Account that might enable a malicious actor to escalate their privileges beneath sure situations.

The failings are listed under –

  • CVE-2025-21396 (CVSS rating: 7.5) – Microsoft Account Elevation of Privilege Vulnerability
  • CVE-2025-21415 (CVSS rating: 9.9) – Azure AI Face Service Elevation of Privilege Vulnerability

“Authentication bypass by spoofing in Azure AI Face Service permits a licensed attacker to raise privileges over a community,” Microsoft in an advisory for CVE-2025-21415, crediting an nameless researcher for reporting the flaw.

Cybersecurity

CVE-2025-21396, alternatively, stems from a case of lacking authorization that might allow an unauthorized attacker to raise privileges over a community. A safety researcher who goes by the alias Sugobet has been acknowledged for locating it.

The tech big additionally famous that it is conscious of the existence of a proof-of-concept (PoC) exploit code for CVE-2025-21415, including each vulnerabilities have been absolutely mitigated. The shortcomings require no buyer motion.

The advisories are a part of Microsoft’s ongoing efforts to enhance transparency by issuing CVEs for vital cloud service vulnerabilities, regardless of whether or not clients want to put in a patch or take different actions to safe themselves.

“As our trade matures and more and more migrates to cloud-based providers, we should be clear about vital cybersecurity vulnerabilities which might be discovered and glued,” it famous again in June 2024.

“By brazenly sharing details about vulnerabilities which might be found and resolved, we allow Microsoft and our companions to be taught and enhance. This collaborative effort contributes to the security and resilience of our vital infrastructure.”

Discovered this text attention-grabbing? This text is a contributed piece from certainly one of our valued companions. Comply with us on Twitter and LinkedIn to learn extra unique content material we publish.



Related Articles

LEAVE A REPLY

Please enter your comment!
Please enter your name here

Latest Articles