Resource Allocation Vulnerability in Azure Access Technology Products by Microsoft
CVE-2025-11832

10CRITICAL

Key Information:

Vendor
CVE Published:
15 October 2025

What is CVE-2025-11832?

A vulnerability exists in Microsoft Azure Access Technology products BLU-IC2 and BLU-IC4, allowing for resource flooding due to improper resource allocation and lack of throttling mechanisms. This could enable malicious entities to exploit the system's resources, potentially leading to service disruptions. Users of versions prior to 1.19.5 should assess their systems and apply available updates to mitigate this risk. For further information, refer to the security advisory on Azure Access's website.

Affected Version(s)

BLU-IC2 1.0 <= 1.19.5

BLU-IC4 1.0 <= 1.19.5

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Kevin Schaller
Benjamin Lafois
Alexi Bitsios
Sebastian Toscano
Dominik Schneider
.
CVE-2025-11832 : Resource Allocation Vulnerability in Azure Access Technology Products by Microsoft