CVE-2025-29807

CVSS 3.1 Score 8.7 of 10 (high)

Details

Published Mar 21, 2025
CWE ID 94
CWE ID 502

Summary

CVE-2025-29807 is a deserialization vulnerability affecting Microsoft Dataverse. Attackers can exploit this issue by sending untrusted data to the vulnerable system, resulting in code execution over a network. This vulnerability poses a significant risk to authorized users, allowing them to potentially gain unintended access or execute malicious code. Microsoft has released patches to address this issue, and it is recommended that users apply these updates as soon as possible to mitigate the threat. Failure to do so could result in serious consequences, including data theft or system compromise.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share