First published: Tue Apr 15 2025(Updated: )
<p>Uncontrolled search path element in Power Automate allows an authorized attacker to disclose information over a network.</p>
Credit: secure@microsoft.com
Affected Software | Affected Version | How to fix |
---|---|---|
Power Automate Desktop |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-29817 has been rated as a medium severity information disclosure vulnerability.
To fix CVE-2025-29817, ensure you update to the latest version of Microsoft Power Automate for Desktop.
Any authorized user of Microsoft Power Automate for Desktop may be impacted by CVE-2025-29817.
CVE-2025-29817 is classified as an information disclosure vulnerability.
Yes, CVE-2025-29817 can allow an attacker to disclose information over a network.