CVE-2025-59218 is a critical Elevation of Privilege vulnerability affecting Microsoft Entra ID, stemming from improper access control (CWE-284). With a CVSS score of 9.6, successful exploitation requires user interaction and can lead to high confidentiality and integrity impacts, alongside low availability impact. While there is no public exploit code or evidence of active exploitation, the vulnerability has garnered significant community attention with 13 mentions and 2 media articles, indicating high awareness. Organizations should monitor advisories and consider restricting user actions as no patch is currently available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:entra_id:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.