CVE-2025-25002: Microsoft Azure Local Cluster

Medium severity, CVSS 5.7. EPSS: 1.1% chance of exploitation in the next 30 days.

Insertion of sensitive information into log file in Azure Local Cluster allows an authorized attacker to disclose information over an adjacent network.

Affected products

  • Microsoft Azure Local Cluster: before 2411.2 (fixed in 2411.2)

Published 2025-04-08. Last modified 2026-06-17.