Cyber Posture

CVE-2025-47995

Medium

Published: 18 July 2025

Published
18 July 2025
Modified
14 August 2025
KEV Added
Patch
CVSS Score 6.5 CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score 0.0152 81.4th percentile
Risk Priority 14 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2025-47995 is a medium-severity Weak Authentication (CWE-1390) vulnerability in Microsoft Azure Machine Learning. Its CVSS base score is 6.5 (Medium).

Operationally, exploitation aligns with the MITRE ATT&CK technique Exploitation for Privilege Escalation (T1068); ranked in the top 18.6% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.

This vulnerability is AI-related — categorised as Other Platforms; in the Other ATLAS/OWASP Terms risk domain.

Threat & Defense at a Glance

What attackers do: exploitation maps to Exploitation for Privilege Escalation (T1068).
Threat & Defense Details

Likely Mitigating ControlsAI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-1390

Helps detect exploitation of weak authentication mechanisms by notifying of previous unauthorized logons.

addresses: CWE-1390

The IA policy requires strong authentication methods, reducing use of weak authentication.

addresses: CWE-1390

Enforces dynamic, context-aware authentication that mitigates weak static authentication by increasing requirements based on risk or conditions.

addresses: CWE-1390

Enforces authentication for users, reducing the viability of weak authentication mechanisms.

addresses: CWE-1390

Requires authentication mechanisms to meet applicable standards and guidelines, preventing weak authentication.

MITRE ATT&CK Enterprise TechniquesAI

T1068 Exploitation for Privilege Escalation Privilege Escalation
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.
Why these techniques?

Weak authentication in Azure Machine Learning enables an authorized attacker to elevate privileges over a network, directly facilitating T1068: Exploitation for Privilege Escalation.

NVD Description

Weak authentication in Azure Machine Learning allows an authorized attacker to elevate privileges over a network.

Deeper analysisAI

CVE-2025-47995 is a weak authentication vulnerability in Azure Machine Learning that allows an authorized attacker to elevate privileges over a network. Published on 2025-07-18, it carries a CVSS v3.1 base score of 6.5 (AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N) and maps to CWE-1390.

The vulnerability can be exploited by an attacker with low privileges (PR:L) over the network (AV:N) with low attack complexity (AC:L) and no user interaction (UI:N). Successful exploitation enables privilege escalation, leading to high confidentiality impact (C:H) without affecting integrity or availability.

The Microsoft Security Response Center advisory at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47995 provides guidance on mitigation and related updates.

Details

CWE(s)

Affected Products

microsoft
azure machine learning
all versions

AI Security AnalysisAI

AI Category
Other Platforms
Risk Domain
Other ATLAS/OWASP Terms
OWASP Top 10 for LLMs 2025
None mapped
Classification Reason
Azure Machine Learning is a cloud-based platform for machine learning workflows, fitting under 'Other Platforms' as it does not match more specific categories like frameworks or libraries.

CVEs Like This One

CVE-2025-49747Same product: Microsoft Azure Machine Learning
CVE-2025-49746Same product: Microsoft Azure Machine Learning
CVE-2026-32207Same product: Microsoft Azure Machine Learning
CVE-2025-60710Same vendor: Microsoft
CVE-2026-32090Same vendor: Microsoft
CVE-2026-27916Same vendor: Microsoft
CVE-2025-54914Same vendor: Microsoft
CVE-2025-21358Same vendor: Microsoft
CVE-2026-21244Same vendor: Microsoft
CVE-2026-24293Same vendor: Microsoft

References