CVE-2025-21384

CVSS 3.1 Score 8.3 of 10 (high)

Details

Published Apr 1, 2025
CWE ID 693

Summary

CVE-2025-21384 is a newly disclosed Server-Side Request Forgery (SSRF) vulnerability affecting Microsoft Azure Health Bot. An authenticated attacker can exploit this flaw to launch network-level attacks, gaining elevated privileges beyond their intended access scope. This issue poses a significant risk to organizations utilizing Azure Health Bot, requiring urgent patching to mitigate potential harm.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share