CVE-2025-21396: Microsoft Account

High severity, CVSS 8.2. EPSS: 0.7% chance of exploitation in the next 30 days.

Missing authorization in Microsoft Account allows an unauthorized attacker to elevate privileges over a network.

Affected products

  • Microsoft Account: affected versions not specified

Published 2025-01-29. Last modified 2026-06-17.