Microsoft has fixed four critical flaws that affect key cloud services, including Azure DevOps, Azure Automation, Azure Storage , and Microsoft Power Apps.
See also: Oracle confirms Cloud breach to customers

These critical vulnerabilities, disclosed on May 9, 2025, could potentially allow attackers to gain elevated privileges and compromise cloud environments. However, Microsoft confirms that none of them have been actively exploited. These vulnerabilities highlight the ever-increasing complexity and interconnectedness of cloud platforms, underscoring the need for robust security measures and ongoing monitoring.
The most severe vulnerability, codenamed CVE-2025-29813, received the maximum CVSS score of 10.0 and affected Azure DevOps pipelines.
This critical privilege escalation flaw allowed attackers with project-level access to exchange temporary pipeline job tokens for long-lived tokens, effectively extending their access to entire project environments.
Microsoft engineers identified the root cause in how Visual Studio incorrectly handles pipeline task tokens and implemented a fix to the token management logic to prevent privilege escalation.
Azure Automation Services was affected by the flaw CVE-2025-29827 (CVSS score 9.9), where inadequate authorization checks allowed authenticated users to escalate their privileges over the network.
See also: Cloudflare announces OpenPubkey SSH
This vulnerability posed particular risks in multi-tenant environments, as it exploited weaknesses in the authorization framework, based on CWE-285 (Insufficient Authorization).

Another critical flaw, codenamed CVE-2025-29972 (CVSS score 9.9), exploited server-side request forgery (SSRF) vectors in the Azure Storage Resource Provider.
This spoofing vulnerability allowed authorized attackers to create requests that impersonated other systems or users, which could lead to unauthorized access to data.
The fourth vulnerability, CVE-2025-47733 (CVSS score 9.1), affected Microsoft Power Apps and could allow unauthorized attackers to disclose sensitive information via SSRF techniques.
In contrast to the other vulnerabilities, this one did not require prior authentication, a fact that significantly increased its potential impact in case it was not addressed immediately.
See also: BadRAM vulnerability puts Cloud data at risk
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Related to the above is the fact that SSRF (Server-Side Request Forgery) vulnerabilities are becoming increasingly prevalent in cloud environments , as they allow attackers to “trick” the server into making requests on their behalf, often to internal services that would otherwise not be accessible. In the context of multi-tenant platforms like Azure, such flaws become even more serious, because they can lead to a violation of isolation between clients , which is a foundation of cloud security
Source: cybersecuritynews
