Vulnerability Description
Improper access control in Azure Virtual Machines allows an authorized attacker to perform spoofing locally.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Microsoft | Ecesv6-Series Azure Vm Firmware | - |
| Microsoft | Ecesv6-Series Azure Vm | - |
| Microsoft | Dcesv6-Series Azure Vm Firmware | - |
| Microsoft | Dcesv6-Series Azure Vm | - |
| Microsoft | Nccadsh100V5-Series Azure Vm Firmware | - |
| Microsoft | Nccadsh100V5-Series Azure Vm | - |
| Microsoft | Ecedsv5-Series Azure Vm Firmware | - |
| Microsoft | Ecedsv5-Series Azure Vm | - |
| Microsoft | Ecesv5-Series Azure Vm Firmware | - |
| Microsoft | Ecesv5-Series Azure Vm | - |
| Microsoft | Dcedsv5-Series Azure Vm Firmware | - |
| Microsoft | Dcedsv5-Series Azure Vm | - |
| Microsoft | Dcesv5-Series Azure Vm Firmware | - |
| Microsoft | Dcesv5-Series Azure Vm | - |
| Microsoft | Ecadsv5-Series Azure Vm Firmware | - |
| Microsoft | Ecadsv5-Series Azure Vm | - |
| Microsoft | Ecasv5-Series Azure Vm Firmware | - |
| Microsoft | Ecasv5-Series Azure Vm | - |
| Microsoft | Dcadsv5-Series Azure Vm Firmware | - |
| Microsoft | Dcadsv5-Series Azure Vm | - |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2025-49707?
CVE-2025-49707 is a vulnerability with a CVSS score of 7.9 (HIGH). Improper access control in Azure Virtual Machines allows an authorized attacker to perform spoofing locally.
How severe is CVE-2025-49707?
CVE-2025-49707 has been rated HIGH with a CVSS base score of 7.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-49707?
Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Ecesv6-Series Azure Vm Firmware, Microsoft Ecesv6-Series Azure Vm, Microsoft Dcesv6-Series Azure Vm Firmware, Microsoft Dcesv6-Series Azure Vm, Microsoft Nccadsh100V5-Series Azure Vm Firmware.