CVE-2025-30390: Azure ML Compute Elevation of Privilege Vulnerability
Published Apr 30, 2025
·Updated
Azure ML Compute Elevation of Privilege Vulnerability
Other sources
Improper authorization in Azure allows an authorized attacker to elevate privileges over a network.
— Microsoft
Affected Software
2 affected components
Microsoft Azure Machine Learning
Microsoft Azure Machine Learning
Event History
Apr 30, 2025
CVE Published
via Microsoft·07:00 AM
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
Description
CVE Published
via MITRE·05:14 PM
Data Sourced
via MITRE·05:14 PM
DescriptionSeverity
Frequently Asked Questions
1
What is the severity of CVE-2025-30390?
CVE-2025-30390 has a high severity rating due to improper authorization in Azure that allows privilege escalation.
2
How do I mitigate CVE-2025-30390?
Mitigation for CVE-2025-30390 involves applying security updates provided by Microsoft for Azure Machine Learning.
3
Who is affected by CVE-2025-30390?
CVE-2025-30390 affects users of Microsoft Azure Machine Learning who may be susceptible to unauthorized privilege escalation.
4
When was CVE-2025-30390 disclosed?
CVE-2025-30390 was disclosed in the year 2025.
5
What type of vulnerability is CVE-2025-30390?
CVE-2025-30390 is classified as an Elevation of Privilege vulnerability in Azure.