CVE-2025-21415

Authentication bypass by spoofing in Azure AI Face Service allows an authorized attacker to elevate privileges over a network.
Configurations

Configuration 1 (hide)

cpe:2.3:a:microsoft:azure_ai_face_service:-:*:*:*:*:*:*:*

History

07 Feb 2025, 14:11

Type Values Removed Values Added
CPE cpe:2.3:a:microsoft:azure_ai_face_service:-:*:*:*:*:*:*:*
References () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21415 - () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21415 - Vendor Advisory
Summary
  • (es) La omisión de autenticación mediante suplantación de identidad en Azure AI Face Service permite que un atacante autorizado eleve privilegios en una red.
First Time Microsoft azure Ai Face Service
Microsoft

29 Jan 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-01-29 23:15

Updated : 2025-02-07 14:11


NVD link : CVE-2025-21415

Mitre link : CVE-2025-21415

CVE.ORG link : CVE-2025-21415


JSON object : View

Products Affected

microsoft

  • azure_ai_face_service
CWE
CWE-290

Authentication Bypass by Spoofing