CVE-2025-49752 is a critical Elevation of Privilege vulnerability affecting Microsoft Azure Bastion Developer. With a CVSS score of 10.0, it presents a severe risk, allowing unauthenticated attackers to achieve high confidentiality and integrity impacts with low availability impact over the network. Despite its critical severity and high community discussion, there is currently no evidence of active exploitation, nor are public exploit codes available in Metasploit, Nuclei, or ExploitDB. Organizations using Azure Bastion Developer should prioritize patching to mitigate this significant threat.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:azure_bastion_developer:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.