Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-59218

34
FAUCET Score

CVE-2025-59218 is a critical Elevation of Privilege vulnerability affecting Microsoft Entra ID, stemming from improper access control (CWE-284). With a CVSS score of 9.6, successful exploitation requires user interaction and can lead to high confidentiality and integrity impacts, alongside low availability impact. While there is no public exploit code or evidence of active exploitation, the vulnerability has garnered significant community attention with 13 mentions and 2 media articles, indicating high awareness. Organizations should monitor advisories and consider restricting user actions as no patch is currently available.

Impacted Technologies

VendorProductVersion(s)CPE
Range not provided by sourceCPE matchmatch criteria
cpe:2.3:a:microsoft:entra_id:-:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.6CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:L

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
LOW
Exploitability Score
2.8
Impact Score
6.0
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.62%
Probability of exploitation in next 30 days
EPSS Percentile
46.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.0062 is in the 51st percentile among its peer group of 834 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.

Remediation

Vendor Patches (1)

microsoftvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

microsoft2025-Oct/CVE-2025-59218Critical

Azure Entra ID Elevation of Privilege Vulnerability

Oct 14, 2025

References

msrc.microsoft.com / update-guide/vulnerability/CVE-2025-59218
Vendor Advisory