CVE-2025-29827: Azure Automation Elevation of Privilege Vulnerability
Published May 8, 2025
·Updated
Azure Automation Elevation of Privilege Vulnerability
Other sources
Improper authorization in Azure Automation allows an authorized attacker to elevate privileges over a network.
— Microsoft
Affected Software
2 affected components
Microsoft Azure Automation
Microsoft Azure Automation
Event History
May 8, 2025
CVE Published
via Microsoft·07:00 AM
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
CVE Published
via MITRE·10:17 PM
Data Sourced
via MITRE·10:17 PM
DescriptionSeverity
May 14, 2025
News Published
via The Register·12:44 AM
News Published
via The Register·12:48 AM
May 18, 2025
Known Exploited
12:49 AM
Jul 24, 2026
News Published
via Dark Reading·12:48 PM
Aug 5, 2026
News Published
via Dark Reading·03:11 AM
Frequently Asked Questions
1
What is the severity of CVE-2025-29827?
CVE-2025-29827 is classified as an elevation of privilege vulnerability.
2
How do I fix CVE-2025-29827?
To resolve CVE-2025-29827, ensure you apply the latest updates and patches provided by Microsoft for Azure Automation.
3
Who is affected by CVE-2025-29827?
Any users of Microsoft Azure Automation with inadequate authorization controls are affected by CVE-2025-29827.
4
What type of vulnerability is CVE-2025-29827?
CVE-2025-29827 is categorized as an improper authorization vulnerability that allows privilege escalation.
5
Can CVE-2025-29827 be exploited remotely?
Yes, CVE-2025-29827 can be exploited remotely by an authorized attacker over a network.