CVE-2025-29819: Windows Admin Center in Azure Portal Information Disclosure Vulnerability

6.2 CVSS

Description

External control of file name or path in Azure Portal Windows Admin Center allows an unauthorized attacker to disclose information locally.

Classification

CVE ID: CVE-2025-29819

CVSS Base Severity: MEDIUM

CVSS Base Score: 6.2

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C

Problem Types

CWE-73: External Control of File Name or Path

Affected Products

Vendor: Microsoft, Microsoft

Product: Windows Admin Center in Azure Portal, Windows Admin Center

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.07% (probability of being exploited)

EPSS Percentile: 22.71% (scored less or equal to compared to others)

EPSS Date: 2025-04-18 (when was this score calculated)

References

https://nvd.nist.gov/vuln/detail/CVE-2025-29819
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29819

Timeline