Elevation of Privilege Vulnerability in Azure Service Fabric by Microsoft
CVE-2025-21195

6MEDIUM

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
8 July 2025

What is CVE-2025-21195?

A vulnerability in Azure Service Fabric allows authorized users to potentially elevate their privileges by exploiting improper link resolution before file access. This flaw can enable attackers to gain additional rights within the system, compromising the integrity of services and data. Proper attention to security practices and timely updates are essential to safeguard against this vulnerability.

Affected Version(s)

Service Fabric Unknown 1.0.0 < 10.1 Cumulative Update 7.0

References

CVSS V3.1

Score:
6
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.