CVE-2025-29813: Azure DevOps Server Elevation of Privilege Vulnerability
Published May 8, 2025
·Updated
[Spoofable identity claims] Authentication Bypass by Assumed-Immutable Data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.
Other sources
Azure DevOps Elevation of Privilege Vulnerability
— Microsoft
Affected Software
2 affected components
Microsoft Azure DevOps
Microsoft Azure DevOps
Event History
May 8, 2025
CVE Published
via Microsoft·07:00 AM
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
CVE Published
via MITRE·10:17 PM
Data Sourced
via MITRE·10:17 PM
DescriptionSeverity
Data Sourced
via NVD·11:15 PM
DescriptionSeverityWeaknessAffected Software
May 14, 2025
News Published
via The Register·12:44 AM
News Published
via The Register·12:48 AM
May 18, 2025
Known Exploited
12:49 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-29813?
CVE-2025-29813 is classified as an elevation of privilege vulnerability.
2
How do I fix CVE-2025-29813?
To fix CVE-2025-29813, ensure you apply the latest updates from Microsoft for Azure DevOps.
3
Who is affected by CVE-2025-29813?
CVE-2025-29813 affects users of Microsoft Azure DevOps if they are using affected versions.
4
What could an attacker do if they exploit CVE-2025-29813?
If exploited, CVE-2025-29813 could allow an attacker to extend their access to projects within Azure DevOps.
5
How can I determine if I am vulnerable to CVE-2025-29813?
You can determine vulnerability by checking if your version of Microsoft Azure DevOps is listed as affected in the security advisory.