PT-2025-7540 · Microsoft · Bing

Nicolas Joly

·

Published

2025-02-19

·

Updated

2025-03-12

·

CVE-2025-21355

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Bing (affected versions not specified)
Description The issue is related to missing authentication for a critical function in Microsoft Bing, allowing an unauthorized attacker to execute code over a network. This is due to inadequate authentication mechanisms in a critical Bing service component. The estimated number of potentially affected devices worldwide is not provided. There is information about real-world incidents where this issue was exploited, as it is mentioned that the vulnerability was actively exploited.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. However, it is mentioned that Microsoft has addressed the critical security flaw, and there is no action for users of this service to take, as the vulnerability has already been fully mitigated by Microsoft.

RCE

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-01962
CVE-2025-21355

Affected Products

Bing