CVE-2025-21415
CVSS 3.1 Score 8.8 of 10 (high)
Details
Summary
CVE-2025-21415 is a new vulnerability affecting Microsoft Azure AI Face Service. An attacker can successfully bypass authentication, allowing them to elevate privileges over a network. This spoofing attack grants unauthorized access to the service, putting sensitive data at risk. The vulnerability could potentially be exploited remotely, making it a significant security concern for organizations utilizing this service. Microsoft has not yet released a patch for this issue, leaving affected users vulnerable until a fix is available. It is strongly recommended that users implement additional security measures to mitigate risk until a patch is issued.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.