CVE-2025-29813

Published May 8, 2025

Last updated 21 days ago

Overview

Description
[Spoofable identity claims] Authentication Bypass by Assumed-Immutable Data in Azure DevOps allows an unauthorized attacker to elevate privileges over a network.
Source
secure@microsoft.com
NVD status
Analyzed
CNA Tags
exclusively-hosted-service

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

secure@microsoft.com
CWE-302
nvd@nist.gov
CWE-287

Social media

Hype score
Not currently trending
  1. Actively exploited CVE : CVE-2025-29813

    @transilienceai

    18 May 2025

    9 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  2. ماکروسافت به تازگی برای ۴ آسیب پذیری که برای سرویس Azure cloud و Power Apps منتشر شده است ، پچ لازم را ارائه داده است. این آسیب پذیری ها دارای کدهای شناسایی CVE-2025-29813 و

    @AmirHossein_sec

    18 May 2025

    32 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  3. Actively exploited CVE : CVE-2025-29813

    @transilienceai

    17 May 2025

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  4. ⚠️Actualizaciones mensuales de Microsoft ❗CVE-2025-29813 ❗CVE-2025-29972 ❗CVE-2025-29827 ❗CVE-2025-47733 ➡️Más info: https://t.co/bB03utcmcw https://t.co/uwmTwujltX

    @CERTpy

    16 May 2025

    116 Impressions

    2 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. 📌 Microsoft confirms 4 critical vulnerabilities in Azure and Power Apps. CVE-2025-29813 scores 10/10 CVSS. All patched. #CyberSecurity #CloudSecurity https://t.co/SLj7sG17Yj https://t.co/pobyq6oA99

    @CyberHub_blog

    15 May 2025

    4 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🚨 Microsoft Patch Tuesday: 78 Flaws, 5 Zero-Days Exploited! 🔍 28 RCE, 20 EoP bugs fixed 🔐 SAP NetWeaver critical flaw (CVE-2025-42999) patched Patch NOW: ✅ CVE-2025-30400 (Win DWM Core) ✅ CVE-2025-29813 (Azure, CVSS 10.0) 🛡️ Protect your systems #PatchTuesday #

    @CyberWolfGuard

    15 May 2025

    42 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Vulnerabilidades críticas de seguridad en la nube de Microsoft CVE-2025-29813 Azure DevOps Elevation of Privilege CVE-2025-29972 Azure Storage Resource Provider Spoofing CVE-2025-29827 Azure Automation Elevation of Privilege https://t.co/fSALC0mUZN https://t.co/V3lGgKu0kG

    @elhackernet

    13 May 2025

    2341 Impressions

    10 Retweets

    16 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  8. Elevation of Privilege Vulnerability in Visual Studio (CVE-2025-29813) #CVE202529813 #ElevationofPrivilegeVulnerability #Microsoft #MicrosoftVisualStudio https://t.co/BnGqauTzZt https://t.co/DjeVB6Ohum

    @SystemTek_UK

    12 May 2025

    34 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  9. 🚨 CVE-2025-29813 ⚠️🔴 CRITICAL (10) 🏢 Microsoft - Azure DevOps 🏗️ N/A 🔗 https://t.co/ptx9pGYUja #CyberCron #VulnAlert #InfoSec https://t.co/pT1SP9YdG2

    @cybercronai

    9 May 2025

    25 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. By me @Forbes: A CVSS 10 Azure vulnerability confirmed by Microsoft. CVE-2025-29813 #infosec https://t.co/dDuIecDRZA

    @happygeek

    9 May 2025

    161 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  11. [1/7] 🚨 @Microsoft just patched CVE-2025-29813, a severe Azure DevOps vulnerability with a perfect CVSS score of 10.0! This flaw allowed attackers to swap short-term pipeline tokens for long-term ones, potentially extending their access. No user action needed. @AzureDevOps htt

    @gothburz

    9 May 2025

    86 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.