CVE-2025-49707
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Exploitability: 1.8 / Impact: 3.6
Source: NVD
Description
Improper access control in Azure Virtual Machines allows an authorized attacker to perform spoofing locally.
Affected (11)
Products: Microsoft: Ecesv6 Series Azure Vm Firmware, Dcesv6 Series Azure Vm Firmware, Nccadsh100v5 Series Azure Vm Firmware, Ecedsv5 Series Azure Vm Firmware, Ecesv5 Series Azure Vm Firmware, Dcedsv5 Series Azure Vm Firmware, Dcesv5 Series Azure Vm Firmware, Ecadsv5 Series Azure Vm Firmware, Ecasv5 Series Azure Vm Firmware, Dcadsv5 Series Azure Vm Firmware, Dcasv5 Series Azure Vm Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Microsoft Ecesv6 Series Azure Vm | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Microsoft Dcesv6 Series Azure Vm | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Microsoft Nccadsh100v5 Series Azure Vm | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Microsoft Ecedsv5 Series Azure Vm | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Microsoft Ecesv5 Series Azure Vm | All versions |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Microsoft Dcedsv5 Series Azure Vm | All versions |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Microsoft Dcesv5 Series Azure Vm | All versions |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Microsoft Ecadsv5 Series Azure Vm | All versions |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Microsoft Ecasv5 Series Azure Vm | All versions |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Microsoft Dcadsv5 Series Azure Vm | All versions |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Microsoft Dcasv5 Series Azure Vm | All versions |
References (1)
Source: secure@microsoft.com
Vendor Advisory
Timeline
No history available yet.