Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-20657 | Improper link resolution before file access ('link following') in Service Fabric allows an authorized attacker to elevate privileges locally. |
Fri, 13 Feb 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Azure
Azure service Fabric |
|
| CPEs | cpe:2.3:a:azure:service_fabric:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Azure
Azure service Fabric |
Tue, 22 Jul 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft azure Service Fabric
|
|
| CPEs | cpe:2.3:a:microsoft:azure_service_fabric:*:*:*:*:*:*:*:* cpe:2.3:a:microsoft:azure_service_fabric:10.1:-:*:*:*:*:*:* cpe:2.3:a:microsoft:azure_service_fabric:10.1:cumulative_update_2:*:*:*:*:*:* cpe:2.3:a:microsoft:azure_service_fabric:10.1:cumulative_update_3:*:*:*:*:*:* cpe:2.3:a:microsoft:azure_service_fabric:10.1:cumulative_update_4:*:*:*:*:*:* cpe:2.3:a:microsoft:azure_service_fabric:10.1:cumulative_update_5:*:*:*:*:*:* cpe:2.3:a:microsoft:azure_service_fabric:10.1:cumulative_update_6:*:*:*:*:*:* |
|
| Vendors & Products |
Microsoft azure Service Fabric
|
Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 08 Jul 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 08 Jul 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper link resolution before file access ('link following') in Service Fabric allows an authorized attacker to elevate privileges locally. | |
| Title | Azure Service Fabric Runtime Elevation of Privilege Vulnerability | |
| Weaknesses | CWE-59 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-02-13T19:06:37.177Z
Reserved: 2024-12-05T21:43:30.767Z
Link: CVE-2025-21195
Updated: 2025-07-08T19:26:15.507Z
Status : Analyzed
Published: 2025-07-08T17:15:33.037
Modified: 2025-07-22T17:50:17.987
Link: CVE-2025-21195
No data.
OpenCVE Enrichment
Updated: 2025-07-13T21:47:17Z
EUVD