CVE-2025-21195: Azure Service Fabric Runtime Elevation of Privilege Vulnerability
Azure Service Fabric Runtime Elevation of Privilege Vulnerability
Other sources
Improper link resolution before file access ('link following') in Service Fabric allows an authorized attacker to elevate privileges locally.
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-21195?
CVE-2025-21195 has been rated as a significant elevation of privilege vulnerability.
How do I fix CVE-2025-21195?
To fix CVE-2025-21195, ensure you update Azure Service Fabric to the latest available version to mitigate the vulnerability.
Who is affected by CVE-2025-21195?
CVE-2025-21195 affects users of Microsoft Azure Service Fabric who have not applied the appropriate security patches.
Can CVE-2025-21195 be exploited remotely?
CVE-2025-21195 requires local access, which means an attacker must have authorized access to exploit this vulnerability.
What are the potential impacts of CVE-2025-21195?
Exploitation of CVE-2025-21195 could allow an attacker to elevate their privileges and gain unauthorized access to sensitive operations within Azure Service Fabric.