Azure Bot Service Elevation of Privilege Vulnerability
PUBLISHED5.1CWE-284exclusively-hosted-service
Azure Bot Service Elevation of Privilege Vulnerability
Problem type
Affected products
Microsoft
Azure Bot Service
N/A - AFFECTED
References
JSON source
Click to expand
{ "dataType": "CVE_RECORD", "dataVersion": "5.1", "cveMetadata": { "cveId": "CVE-2025-55244", "assignerOrgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8", "assignerShortName": "microsoft", "dateUpdated": "2025-09-25T23:11:19.439Z", "dateReserved": "2025-08-11T20:26:16.633Z", "datePublished": "2025-09-04T23:09:49.557Z", "state": "PUBLISHED" }, "containers": { "cna": { "providerMetadata": { "orgId": "f38d906d-7342-40ea-92c1-6c4a2c6478c8", "shortName": "microsoft", "dateUpdated": "2025-09-25T23:11:19.439Z" }, "datePublic": "2025-09-04T07:00:00.000Z", "title": "Azure Bot Service Elevation of Privilege Vulnerability", "descriptions": [ { "lang": "en-US", "value": "Azure Bot Service Elevation of Privilege Vulnerability" } ], "affected": [ { "vendor": "Microsoft", "product": "Azure Bot Service", "platforms": [ "Unknown" ], "versions": [ { "version": "N/A", "status": "affected" } ] } ], "problemTypes": [ { "descriptions": [ { "lang": "en-US", "description": "CWE-284: Improper Access Control", "cweId": "CWE-284", "type": "CWE" } ] } ], "references": [ { "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-55244", "name": "Azure Bot Service Elevation of Privilege Vulnerability", "tags": [ "vendor-advisory" ] } ], "metrics": [ { "format": "CVSS", "scenarios": [ { "lang": "en-US", "value": "GENERAL" } ], "cvssV3_1": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C", "baseScore": 9, "baseSeverity": "CRITICAL" } } ], "tags": [ "exclusively-hosted-service" ] }, "adp": [ { "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2025-09-10T03:56:01.010Z" }, "title": "CISA ADP Vulnrichment", "metrics": [ {} ] } ] } }