CVE-2025-47158: Azure DevOps Server Elevation of Privilege Vulnerability
Authentication bypass by assumed-immutable data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.
Other sources
Azure DevOps Server Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47158?
CVE-2025-47158 has been rated as a high-severity vulnerability due to its capability for unauthorized privilege escalation.
How do I fix CVE-2025-47158?
To fix CVE-2025-47158, it is recommended to apply the latest security updates provided by Microsoft for Azure DevOps.
Who is affected by CVE-2025-47158?
CVE-2025-47158 affects users of Microsoft Azure DevOps who have not patched their systems against this vulnerability.
What type of vulnerability is CVE-2025-47158?
CVE-2025-47158 is categorized as an Elevation of Privilege vulnerability that allows attackers to bypass authentication.
Can CVE-2025-47158 be exploited remotely?
Yes, CVE-2025-47158 can be exploited over a network, enabling attackers to gain unauthorized access from remote locations.