CVE-2025-53765

EUVD-2025-24290
Exposure of private personal information to an unauthorized actor in Azure Stack allows an authorized attacker to disclose information locally.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
microsoftCNA
4.4 MEDIUM
LOCAL
LOW
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
Base Score
CVSS 3.x
EPSS Score
Percentile: 68%
Affected Products (NVD)
VendorProductVersion
microsoftazure_app_service_on_azure_stack
𝑥
< 102.10.2.11
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
microsoftazure_stack_hub
1.0.0 ≤
𝑥
< 102.10.2.11
CNA