Article Details

Scrape Timestamp (UTC): 2025-02-04 05:12:21.292

Source: https://thehackernews.com/2025/02/microsoft-patches-critical-azure-ai.html

Original Article Text

Click to Toggle View

Microsoft Patches Critical Azure AI Face Service Vulnerability with CVSS 9.9 Score. Microsoft has released patches to address two Critical-rated security flaws impacting Azure AI Face Service and Microsoft Account that could allow a malicious actor to escalate their privileges under certain conditions. The flaws are listed below - "Authentication bypass by spoofing in Azure AI Face Service allows an authorized attacker to elevate privileges over a network," Microsoft in an advisory for CVE-2025-21415, crediting an anonymous researcher for reporting the flaw. CVE-2025-21396, on the other hand, stems from a case of missing authorization that could permit an unauthorized attacker to elevate privileges over a network. A security researcher who goes by the alias Sugobet has been acknowledged for discovering it. The tech giant also noted that it's aware of the existence of a proof-of-concept (PoC) exploit code for CVE-2025-21415, adding both vulnerabilities have been fully mitigated. The shortcomings require no customer action. The advisories are part of Microsoft's ongoing efforts to improve transparency by issuing CVEs for critical cloud service vulnerabilities, irrespective of whether customers need to install a patch or take other actions to secure themselves. "As our industry matures and increasingly migrates to cloud-based services, we must be transparent about significant cybersecurity vulnerabilities that are found and fixed," it noted back in June 2024. "By openly sharing information about vulnerabilities that are discovered and resolved, we enable Microsoft and our partners to learn and improve. This collaborative effort contributes to the safety and resilience of our critical infrastructure."

Daily Brief Summary

MALWARE // Microsoft Addresses Severe Azure AI and Account Vulnerabilities

Microsoft recently patched critical-rated security flaws in Azure AI Face Service and Microsoft Account.

An authentication bypass by spoofing vulnerability in Azure AI, identified as CVE-2025-21415, could allow privileged escalation.

Another vulnerability, CVE-2025-21396, involves missing authorization and could also enable unauthorized privilege escalation.

Both vulnerabilities were critically rated with a CVSS score of 9.9 and are now fully mitigated without requiring any customer action.

A proof-of-concept exploit was known for CVE-2025-21415, highlighting potential risk prior to the fix.

Microsoft credited an anonymous researcher and a security researcher known as Sugobet for discovering the flaws.

The company emphasized its commitment to transparency and the importance of sharing information on resolved vulnerabilities to strengthen cybersecurity resilience.

These patches are part of Microsoft's ongoing initiative to address and disclose vulnerabilities in cloud services, enhancing overall security infrastructure.