Vulnerability Database

309,136

Total vulnerabilities in the database

CVE-2025-21195

Improper link resolution before file access ('link following') in Service Fabric allows an authorized attacker to elevate privileges locally.

  • Published: Jul 8, 2025
  • Updated: Nov 16, 2025
  • CVE: CVE-2025-21195
  • Severity: Medium
  • Exploit:

CVSS v3:

  • Severity: Medium
  • Score: 6
  • AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:H/A:H

CWEs:

Software From Fixed in
microsoft / azure_service_fabric - 10.1
microsoft / azure_service_fabric 10.1 10.1.x
microsoft / azure_service_fabric 10.1-cumulative_update_2 10.1-cumulative_update_2.x
microsoft / azure_service_fabric 10.1-cumulative_update_3 10.1-cumulative_update_3.x
microsoft / azure_service_fabric 10.1-cumulative_update_4 10.1-cumulative_update_4.x
microsoft / azure_service_fabric 10.1-cumulative_update_5 10.1-cumulative_update_5.x
microsoft / azure_service_fabric 10.1-cumulative_update_6 10.1-cumulative_update_6.x