PT-2025-47641 · Microsoft · Azure Bastion

Published

2025-11-20

·

Updated

2025-11-28

·

CVE-2025-49752

CVSS v3.1

10

Critical

AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Azure Bastion versions prior to November 20, 2025
Description A critical elevation of privilege flaw impacts Azure Bastion. Attackers can potentially gain higher permissions through capture-replay attacks if the system is unpatched. This allows for authentication bypass.
Recommendations Restrict access to Azure Bastion. Monitor logs for suspicious activity. Enable Multi-Factor Authentication (MFA). Update Azure Bastion to the version released on November 20, 2025.

Fix

LPE

Weakness Enumeration

Related Identifiers

BDU:2025-15486
CVE-2025-49752

Affected Products

Azure Bastion