CVE-2025-4975220.11.2025, 23:15Azure Bastion Elevation of Privilege VulnerabilityEnginsightProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVectorNISTNIST10 CRITICALNETWORKLOWNONECVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:LmicrosoftCNA10 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L/E:U/RL:O/RC:CCISA-ADPADP------Base ScoreCVSS 3.xEPSS ScorePercentile: UnknownVendorProductVersionmicrosoftazure_bastion_developer-𝑥= Vulnerable software versionsCommon Weakness EnumerationCWE-294 - Authentication Bypass by Capture-replayA capture-replay flaw exists when the design of the software makes it possible for a malicious user to sniff network traffic and bypass authentication by replaying it to the server in question to the same effect as the original message (or with minor changes).Referenceshttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-49752