PT-2025-47641 · Microsoft · Azure Bastion

CVE-2025-49752

·

Published

2025-11-20

·

Updated

2025-11-28

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:L
Name of the Vulnerable Software and Affected Versions Azure Bastion versions prior to November 20, 2025
Description A critical elevation of privilege flaw impacts Azure Bastion. Attackers can potentially gain higher permissions through capture-replay attacks if the system is unpatched. This allows for authentication bypass.
Recommendations Restrict access to Azure Bastion. Monitor logs for suspicious activity. Enable Multi-Factor Authentication (MFA). Update Azure Bastion to the version released on November 20, 2025.

Fix

LPE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-15486
CVE-2025-49752

Affected Products

Azure Bastion