Elevation of Privilege Vulnerability in Azure Entra ID by Microsoft
CVE-2025-59218

9.6CRITICAL

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
9 October 2025

What is CVE-2025-59218?

The identified vulnerability in Azure Entra ID allows attackers to exploit specific weaknesses, leading to unauthorized access and elevation of privileges. This can compromise the confidentiality and integrity of sensitive data and facilitate malicious activities within the Azure environment. It is crucial for users and administrators to be aware of this vulnerability and implement necessary security measures to protect their systems.

Affected Version(s)

Microsoft Entra Unknown

References

CVSS V3.1

Score:
9.6
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-59218 : Elevation of Privilege Vulnerability in Azure Entra ID by Microsoft