« Volver al listado

CVE-2025-29819

Estado: AnalizadaMedia (6.2)—

External control of file name or path in Azure Portal Windows Admin Center allows an unauthorized attacker to disclose information locally.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-29819",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-29819",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-04-08T19:17:19.777646Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "secure@microsoft.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.2,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 2.5
      }
    ]
  },
  "affected": [
    {
      "source": "secure@microsoft.com",
      "affectedData": [
        {
          "vendor": "Microsoft",
          "product": "Windows Admin Center",
          "versions": [
            {
              "status": "affected",
              "version": "1809.0",
              "lessThan": "2.4.2.1",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Windows Admin Center in Azure Portal",
          "versions": [
            {
              "status": "affected",
              "version": "1.0",
              "lessThan": "0.45.0.0",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-04-08T18:16:07.520",
  "references": [
    {
      "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-29819",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secure@microsoft.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "secure@microsoft.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-73"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "External control of file name or path in Azure Portal Windows Admin Center allows an unauthorized attacker to disclose information locally."
    },
    {
      "lang": "es",
      "value": "El control externo del nombre o la ruta de archivo en el Centro de administración de Windows del Portal de Azure permite que un atacante no autorizado divulgue información localmente."
    }
  ],
  "lastModified": "2026-06-17T09:05:43.407",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:microsoft:windows_admin_center:*:*:*:*:*:azure:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DFC119D9-F10D-4251-BFF7-36D1E389BD3A",
              "versionEndExcluding": "0.45.0.0"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:windows_admin_center:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D914C78C-0E8A-4E17-835E-147DFC51C170",
              "versionEndExcluding": "2410"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secure@microsoft.com"
}