CVE-2025-27489 is an improper input validation vulnerability in Microsoft Azure Local, affecting Azure Stack HCI 22H2 and 23H2. This flaw allows an authenticated local attacker to achieve privilege escalation with a high CVSS score of 7.8, indicating significant potential for confidentiality, integrity, and availability impacts. While there is no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not currently listed on the KEV catalog, community discussion and media coverage suggest some awareness, with one article mentioning its fix in a recent Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.20348.3328CPE matchmatch criteria | cpe:2.3:o:microsoft:azure_stack_hci_22h2:*:*:*:*:*:*:*:* | ||
< 10.0.25398.1486CPE matchmatch criteria | cpe:2.3:o:microsoft:azure_stack_hci_23h2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.