Microsoft has released security updates to resolve two critical vulnerabilities affecting the Azure AI Face and Microsoft Accounts. These flaws could, under certain circumstances, allow malicious actors to gain elevated privileges.
See also: BadRAM vulnerability puts Cloud data at risk

The vulnerabilities are listed below:
- CVE-2025-21396 (CVSS Score: 7.5) – Microsoft Account Elevation of Privilege Vulnerability
- CVE-2025-21415 (CVSS Score: 9.9) – Azure AI Face Service Elevation of Privilege Vulnerability
“Authentication bypass via spoofing in the Azure AI Face Service allows an authorized attacker to elevate privileges network,” Microsoft said in an advisory for CVE-2025-21415, crediting an anonymous researcher for reporting the flaw.
See also: Microsoft fixes vulnerabilities in various services
CVE -2025-21396 concerns an authorization denial of service vulnerability that could allow an unauthorized attacker to gain elevated privileges on a network. The discovery is attributed to a security researcher using the alias Sugobet .

The tech giant also announced that it is aware of a PoC exploit targeting CVE-2025-21415, clarifying that both vulnerabilities have been fully addressed. It also emphasized that customers do not need to take any action.
The guidance is part of Microsoft to increase transparency by publishing CVEs for critical vulnerabilities in cloud services. This applies regardless of whether customers are required to install patches or take other actions to protect themselves.
See also: Snowflake makes MFA mandatory on all accounts
Azure AI Face Service is an innovative technology that uses artificial intelligence to recognize and analyze facial features. This technology finds application in various areas, such as security, personalized user experiences, and sentiment analysis. It enables users to be identified through biometric data with accuracy and speed, while offering an increased level of convenience and security.
Source: thehackernews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
