PT-2025-7540 · Microsoft · Bing
Nicolas Joly
·
Published
2025-02-19
·
Updated
2025-03-12
·
CVE-2025-21355
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Bing (affected versions not specified)
Description
The issue is related to missing authentication for a critical function in Microsoft Bing, allowing an unauthorized attacker to execute code over a network. This is due to inadequate authentication mechanisms in a critical Bing service component. The estimated number of potentially affected devices worldwide is not provided. There is information about real-world incidents where this issue was exploited, as it is mentioned that the vulnerability was actively exploited.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability. However, it is mentioned that Microsoft has addressed the critical security flaw, and there is no action for users of this service to take, as the vulnerability has already been fully mitigated by Microsoft.
RCE
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Bing