Microsoft has released patches that address two critical-rated security vulnerabilities affecting Azure AI Face Service, Microsoft Account and Microsoft Account. These flaws could allow malicious actors to escalate their privileges in certain circumstances.
Below are the flaws.
CVE-2025-21396 – Microsoft Account Elevation Privilege Vulnerability (CVSS score: 7.5)
CVE-2025-21415 (CVSS score: 9.9) – Azure AI Face Service