CVE-2025-25002 describes an information disclosure vulnerability in Microsoft Azure Local Cluster, where sensitive data is inadvertently logged. An authorized attacker on an adjacent network can exploit this with low complexity to achieve high confidentiality impact. While not actively exploited (KEV: No) and lacking public exploit code, it has garnered some community and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2411.2CPE matchmatch criteria | cpe:2.3:a:microsoft:azure_local_cluster:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.