CVE-2025-53729: Microsoft Azure File Sync Elevation of Privilege Vulnerability
Overview
- Severity
- High (CVSS 7.8)
- CVSS Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
- Category
- Elevation of Privilege
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Less Likely
- Patch Tuesday
- 2025-Aug
- Released
- 2025-08-12
- EPSS Score
- 0.07% (percentile: 21.3%)
Description
Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally.
FAQ
What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Affected Products (4)
Azure
- Azure File Sync v18
- Azure File Sync v19
- Azure File Sync v20
- Azure File Sync v21
Security Updates (4)
Acknowledgments
Michal Kamensky with Microsoft
Revision History
- 2025-08-12: Information published.