CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-53763

CVSS 9.8v3.1pub. 2025-08-21upd. 2025-08-25

Improper access control in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.

🤖 AI Analysis
How it works

The bug consists of improper access control (CWE-284) in Azure Databricks, meaning that permission verification mechanisms are not enforced properly. A remote attacker, without possessing any credentials and without requiring user interaction, can send specially crafted network requests and obtain a higher privilege level than originally granted. The network attack vector with low complexity (AC:L) makes the exploit relatively easy to perform.

Impact

An attacker can gain unauthorized privilege escalation, potentially leading to complete compromise of confidentiality, integrity, and availability of the Azure Databricks environment, including access to processed data and computing resources.

Mitigation & patch

Apply patches available from the manufacturer according to references — details available at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53763

Who is affected

Microsoft Purview Data Governance / Azure Databricks — versions indicated in the manufacturer's references

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Microsoft Purview Data Governance

    APP
    Microsoft
    all versions
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2026-57106CRITICAL10.0PL ✓same product

Krytyczny SSRF w Microsoft Data Quality umożliwiający eskalację uprawnień

CVE-2026-58644CRITICAL9.8⚠ KEVPL ✓same vendor

Zdalne wykonanie kodu poprzez deserializację w Microsoft SharePoint Server

CVE-2026-55040CRITICAL9.1⚠ KEVPL ✓same vendor

Obejście uwierzytelnienia w Microsoft SharePoint Server (RCE-ready)

CVE-2026-50522CRITICAL9.8⚠ KEVPL ✓same vendor

RCE przez deserializację niezaufanych danych w Microsoft SharePoint

CVE-2026-8398CRITICAL9.3⚠ KEVPL ✓same vendor

Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów