CVE-2025-24053
CVSS 3.1 Score 7.2 of 10 (high)
Details
Published Mar 13, 2025
CWE ID 285
Summary
CVE-2025-24053 is a cybersecurity vulnerability affecting Microsoft Dataverse. An attacker who is already authorized can exploit this issue to elevate their privileges over a network. This vulnerability stems from an improper authentication mechanism in Microsoft Dataverse, which allows for unintended access and escalation of privileges. Successful exploitation could lead to significant data compromise or unauthorized system control. Microsoft urges users to update their systems promptly to mitigate this risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.