← Back

CVE-2025-21195

nvd nist
Published: Jul 8, 2025Modified: Jul 22, 2025

JSON object

Loading...
6.0
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:H
Exploitability: 0.8 / Impact: 5.2
Source: secure@microsoft.com (Secondary)

Description

Improper link resolution before file access ('link following') in Service Fabric allows an authorized attacker to elevate privileges locally.

Affected (7)

1 product
Azure Service Fabric
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Microsoft
Before 10.1
Version 10.1
Version 10.1 cumulative_update_2
Version 10.1 cumulative_update_3
Version 10.1 cumulative_update_4
Version 10.1 cumulative_update_5
Version 10.1 cumulative_update_6

References (1)

Timeline

No history available yet.