PT-2025-47641 · Microsoft · Azure Bastion
Published
2025-11-20
·
Updated
2025-11-28
·
CVE-2025-49752
CVSS v3.1
10
Critical
| AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L |
Name of the Vulnerable Software and Affected Versions
Azure Bastion versions prior to November 20, 2025
Description
A critical elevation of privilege flaw impacts Azure Bastion. Attackers can potentially gain higher permissions through capture-replay attacks if the system is unpatched. This allows for authentication bypass.
Recommendations
Restrict access to Azure Bastion.
Monitor logs for suspicious activity.
Enable Multi-Factor Authentication (MFA).
Update Azure Bastion to the version released on November 20, 2025.
Fix
LPE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Azure Bastion