PT-2025-4230 · Microsoft · Azure Ai Face Service

Published

2025-01-29

·

Updated

2025-02-20

·

CVE-2025-21415

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Azure AI Face Service (affected versions not specified)
Description An authentication bypass by spoofing in Azure AI Face Service allows an authorized attacker to elevate privileges over a network. This issue has been exploited in real-world attacks and had a public exploit available. Microsoft has issued critical patches for this flaw, which could let attackers escalate their privileges without authorization, exposing critical infrastructure.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Authentication Bypass by Spoofing

Weakness Enumeration

Related Identifiers

BDU:2025-01635
CVE-2025-21415

Affected Products

Azure Ai Face Service