CVE-2025-21385
massAuthenticated SSRF in Microsoft Purview Enables Information Disclosure
CVE-2025-21385 is a server-side request forgery (SSRF, CWE-918) flaw in Microsoft Purview that lets an authorized, low-privilege user cause the service to make network requests to attacker-influenced or internal endpoints. It is triggered over the network by an authenticated account with no user interaction required, so any tenant user with basic access to the affected Purview functionality is a potential trigger. Successful exploitation has a high confidentiality impact: the attacker can read information from internal resources reachable by the service, without modifying data or disrupting availability. Organizations using the affected Microsoft Purview components are potentially exposed; Microsoft's published data does not specify version ranges or the vulnerable component. No in-the-wild exploitation or public proof-of-concept is known, but the ~24% EPSS score (98th percentile) indicates a high predicted likelihood of exploitation within 30 days.
What to do: Because Microsoft Purview is primarily a cloud service, confirm your tenant has received Microsoft's January 2025 Patch Tuesday service updates and review Microsoft's advisory for any on-prem Purview components (e.g., Information Protection scanner) that need updating. Limit which low-privilege accounts can invoke network requests in Purview, audit the service for unusual outbound or internal requests, and prioritize monitoring given the elevated ~24% 30-day exploitation probability.
| Microsoft Purview | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A Server-Side Request Forgery (SSRF) vulnerability in Microsoft Purview allows an authorized attacker to disclose information over a network.
- Vendors
- microsoft
- Products
- purview
- Weakness
- CWE-918
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N