CVE-2025-53729: Microsoft Azure File Sync
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
Improper access control in Azure File Sync allows an authorized attacker to elevate privileges locally.
Affected products
- Microsoft Azure File Sync: from 18.0.0.0, before 18.3.0.0 (fixed in 18.3.0.0); from 19.0.0.0, before 19.2.0.0 (fixed in 19.2.0.0); from 20.0.0.0, before 20.1.0.0 (fixed in 20.1.0.0); from 21.0.0.0, up to and including 21.1.0.0
Published 2025-08-12. Last modified 2026-06-17.