CVE-2025-21416
CVSS 3.1 Score 8.8 of 10 (high)
Details
Published Apr 30, 2025
Updated: May 12, 2025
CWE ID 862
Summary
CVE-2025-21416 is a cybersecurity vulnerability affecting Azure Virtual Desktop. This issue arises due to a missing authorization mechanism, allowing attackers who have already gained network access to elevate their privileges within the environment. Successful exploitation could result in significant data loss or unauthorized system control. Organizations using Azure Virtual Desktop are strongly advised to apply the available security patch as soon as possible to mitigate this risk. Failure to do so may leave systems vulnerable to attack.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.