CVE-2025-21385 is a Server-Side Request Forgery (SSRF) vulnerability in Microsoft Purview that allows an authorized attacker to disclose information across a network. With a CVSS score of 6.5 (Medium), this vulnerability has a low attack complexity and requires low privileges, enabling information disclosure. While not currently listed in CISA's KEV catalog, its high EPSS and FAUCET Risk Scores, along with community discussion and media coverage, indicate significant concern, though no public exploit code is yet available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:purview:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.