Cyber Security News

Critical Vulnerability in Azure Bastion Let Attackers Bypass Authentication and Escalate privileges

A critical vulnerability in Azure Bastion (CVE-2025-49752) allows remote attackers to bypass authentication mechanisms and escalate privileges to administrative levels.

The flaw, categorized as an authentication bypass vulnerability, poses an immediate risk to organizations that rely on Azure Bastion for secure administrative access to their cloud infrastructure.

Attackers Can Escalate Privileges Without User Interaction

The vulnerability undermines this security model by enabling attackers to gain administrative access through a single network request, potentially compromising all virtual machines accessible through the Bastion host.

According to zeropath, the vulnerability stems from improper handling of authentication tokens within the Bastion service.

Attackers can intercept and replay valid authentication credentials to bypass security controls and assume administrative privileges.

FieldDetails
CVE IDCVE-2025-49752
Vulnerability TypeAuthentication Bypass (CWE-294)
CVSS Score10.0 (Critical)
Affected ProductMicrosoft Azure Bastion (all versions prior to Nov 20, 2025)
Attack VectorNetwork
ImpactRemote Privilege Escalation to Administrative Level

With a CVSS score of 10.0, this vulnerability represents the highest severity classification, indicating it is remotely exploitable, requires no user interaction, and demands no prior authentication.

The critical aspect of CVE-2025-49752 is its network-based exploitability. No physical access, special privileges, or user involvement is necessary for successful exploitation.

An attacker anywhere on the network can compromise the entire Bastion infrastructure and the virtual machines connected to it.

All Azure Bastion deployments before the security update released on November 20, 2025, are vulnerable.

Microsoft has not released specific version numbers, suggesting that the vulnerability affects all configurations using the service.

Zeropath says organizations should quickly check their Azure Bastion setups and make sure all security patches are installed.

This vulnerability adds to a growing list of critical authentication and privilege escalation flaws discovered in Azure services throughout 2025, including CVE-2025-54914 and CVE-2025-29827.

Despite Microsoft’s Secure Future Initiative, aimed at improving security development practices, recurring authentication issues continue to affect Azure infrastructure.

Zeropath Security teams should prioritize patching this vulnerability immediately and conduct a comprehensive audit of administrative access logs to detect any unauthorized activity.

Organizations should also review network segmentation and access controls surrounding their Azure Bastion deployments.

Follow us on Google News, LinkedIn, and X for daily cybersecurity updates. Contact us to feature your stories.

Abinaya

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.

Recent Posts

Google Chrome 153 Update Fixes 42 Security Flaws, Including 3 Critical Ones

Google has released an important Chrome 153 security update that fixes 42 vulnerabilities across the…

4 hours ago

CISA and NIST Release Technical Checklist for Safeguarding Identity Tokens From Theft and Misuse

The Cybersecurity and Infrastructure Security Agency (CISA) and the National Institute of Standards and Technology…

14 hours ago

CISA Shares 17 Techniques Used by Hackers to Compromise Active Directory Environments

CISA and five international cybersecurity agencies have released detailed guidance describing 17 common techniques hackers…

15 hours ago

Apple Rolls Out Massive Security Update Fixing 273 Vulnerabilities Across Its Devices

Apple has released one of its largest coordinated security rollouts, addressing 273 distinct critical vulnerabilities…

15 hours ago

How to Keep Malware’s Rotating Infrastructure From Becoming a Detection Gap

You can’t detect today's attacks with yesterday’s threat intelligence; that’s how you could briefly formulate…

15 hours ago

Microsoft Bans Its AI Models From Launching Cyberattacks or Escalating Their Own Access

Microsoft has published a draft Humanist AI Code of Conduct that would prohibit its in-house…

16 hours ago