ZeroHour

CVE-2025-21385

mass

Authenticated SSRF in Microsoft Purview Enables Information Disclosure

CVSS 3.1
6.5 medium
EPSS
24%p98
Published
()
Modified
AI analysis

CVE-2025-21385 is a server-side request forgery (SSRF, CWE-918) flaw in Microsoft Purview that lets an authorized, low-privilege user cause the service to make network requests to attacker-influenced or internal endpoints. It is triggered over the network by an authenticated account with no user interaction required, so any tenant user with basic access to the affected Purview functionality is a potential trigger. Successful exploitation has a high confidentiality impact: the attacker can read information from internal resources reachable by the service, without modifying data or disrupting availability. Organizations using the affected Microsoft Purview components are potentially exposed; Microsoft's published data does not specify version ranges or the vulnerable component. No in-the-wild exploitation or public proof-of-concept is known, but the ~24% EPSS score (98th percentile) indicates a high predicted likelihood of exploitation within 30 days.

What to do: Because Microsoft Purview is primarily a cloud service, confirm your tenant has received Microsoft's January 2025 Patch Tuesday service updates and review Microsoft's advisory for any on-prem Purview components (e.g., Information Protection scanner) that need updating. Limit which low-privilege accounts can invoke network requests in Purview, audit the service for unusual outbound or internal requests, and prioritize monitoring given the elevated ~24% 30-day exploitation probability.

Affected
Microsoft Purview
Estimated exposure
masslikely millions of enterprise users across Microsoft 365 tenants using Purview (exact count unknown) — Purview is Microsoft's bundled compliance and data-governance suite across Microsoft 365 enterprise plans (hundreds of millions of M365 seats), so plausibly affected users reach the millions range, though only tenants actively using…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A Server-Side Request Forgery (SSRF) vulnerability in Microsoft Purview allows an authorized attacker to disclose information over a network.

Vendors
microsoft
Products
purview
Weakness
CWE-918
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

In the news