Security News > 2025 > February > Microsoft Patches Critical Azure AI Face Service Vulnerability with CVSS 9.9 Score

Microsoft Patches Critical Azure AI Face Service Vulnerability with CVSS 9.9 Score
2025-02-04 05:08

Microsoft has released patches to address two Critical-rated security flaws impacting Azure AI Face Service and Microsoft Account that could allow a malicious actor to escalate their privileges under certain conditions. The flaws are listed below - CVE-2025-21396 (CVSS score: 7.5) - Microsoft Account Elevation of Privilege Vulnerability CVE-2025-21415 (CVSS score: 9.9) - Azure AI Face Service


News URL

https://thehackernews.com/2025/02/microsoft-patches-critical-azure-ai.html

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2025-01-29 CVE-2025-21415 Authentication Bypass by Spoofing vulnerability in Microsoft Azure AI Face Service
Authentication bypass by spoofing in Azure AI Face Service allows an authorized attacker to elevate privileges over a network.
network
low complexity
microsoft CWE-290
8.8
2025-01-29 CVE-2025-21396 Unspecified vulnerability in Microsoft Account
Missing authorization in Microsoft Account allows an unauthorized attacker to elevate privileges over a network.
network
low complexity
microsoft
8.2

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Microsoft 392 52 1467 2973 182 4674