A Critical Vulnerability Rating of 10/10 Has Been Confirmed By Microsoft

00:00 / 00:00 Game-Changing SOC Trends In 2026: AI, SOAR & XDR Shifts

A critical vulnerability score of 10/10 is a very rare circumstance, and Microsoft seems to have caught itself in one of those.

Recently, Microsoft confirmed that its core cloud services were impacted by several critical vulnerabilities, one rated at 10, while the others were rated at 9.9 and 9.1, respectively. As users, what do you do in this situation? Well, nothing! That’s right; Microsoft has also confirmed all their users are protected from the vulnerability and their information is secured tightly.

So, what are these vulnerabilities, and how can we categorize their severity? Four of them were detected, and we can understand the scale they fall into.

CVE-2025-29813: Azure DevOps Elevation of Privilege Vulnerability 

Visual Studio has a significant elevation of privilege vulnerability triggered by inappropriate handling of pipeline job tokens.. It could allow an attacker with access to a project to swap a short-term token for a long-term one, thereby gaining extended access. With a CVSS score of 10.0, the vulnerability is exploitable over the network without requiring privileges or user interaction, and it poses a high risk to confidentiality, integrity, and availability.

CVE-2025-29972: Azure Storage Resource Provider Spoofing Vulnerability

A critical spoofing vulnerability involving Server-Side Request Forgery (SSRF) in Azure. It allows an authorized attacker with low privileges to send unauthorized requests over a network, potentially spoofing internal services. With a CVSS score of 9.9, the vulnerability is easy to exploit, requires no user interaction, and can significantly impact confidentiality, integrity, and availability.

Also read: Everything you need to know about CDSL Malware attack

CVE-2025-29827: Azure Automation Elevation of Privilege Vulnerability

A critical elevation of privilege vulnerability in Azure Automation was caused by improper authorization controls. It enables an attacker with low-level access to escalate their privileges over the network. With a CVSS score of 9.9, this vulnerability poses a high risk to confidentiality and integrity, with moderate impact on availability. It requires no user interaction and is low in complexity to exploit.

Also Read: Critical FortiOS Flaw Allows Unauthorized Access and Full Device Takeover

CVE-2025-47733: Microsoft Power Apps Information Disclosure Vulnerability

This vulnerability ranges to a critical scale of 9.1 and allows an attacker to disclose information over the network. It is a high-severity information disclosure vulnerability in Microsoft Power Apps, stemming from a Server-Side Request Forgery (SSRF) issue.

Though this was a security concern for many individuals and businesses working with Microsoft cloud services, it proved the swiftness of Microsoft to immediately safeguard its customers. As a cybersecurity expert, Secucenter offers a second layer of cyber protection for every organization. We understand the importance of protecting important data from threat actors who are as advanced as the tools that are being invented. Thus, to ensure long-term operations, an organization can always utilize an additional layer of cybersecurity.

Leave a Reply

Your email address will not be published. Required fields are marked *

The Author

Sreekanth

SOC Manager

Sreekanth is the Technical and Professional Services Manager at Secucenter. With over 12 years of expertise in safeguarding IT infrastructures across on-premises, hybrid, and cloud environments, he is dedicated to enhancing security measures. Sreekanth's innovative mindset drives him to develop robust and resilient cybersecurity frameworks.

FEATURED INSIGHTS

Security Intelligence
Hub

What the CDSL Malware Attack Teaches Organizations About VAPT?

Most organizations believe that completing an annual Vulnerability Assessment and Penetration Testing...

Read more ›

White Label SOC Implementation Checklist: 30-Day Launch Plan for MSPs

In a world where cyber threats evolve faster than ever, Managed Service...

Read more ›

White Label SOC Integration: Step-by-Step Implementation Guide for MSPs

In today’s evolving cybersecurity landscape, Managed Service Providers (MSPs) face increasing pressure...

Read more ›

Stop guessing where you're exposed.
Talk to a senior analyst this week.

Get a Free Security Audit

Protect Your Business Today To Scale Tomorrow

Most breaches begin with a gap no one was watching. Tell us what you're protecting and our SOC analysts will pressure-test your defenses and show you exactly where you stand.

Phone

+1 607 360 5504

Sales Office - United States

651, N Broad St, Middletown
Delaware-19709

Operations Center- India

Level 17, TransAsia Cyber Park
Kochi, Kerala-682030

Data privacy notice. All submissions are protected via TLS 1.3 encryption in transit and processed within our secure, air-gapped data environment. We never resell your data.