CVE-2025-64655

8.8

Microsoft · Dynamics OmniChannel SDK Storage Containers

An improper authorization vulnerability in Microsoft Dynamics OmniChannel SDK Storage Containers permits unauthenticated network attackers to achieve unauthorized privilege escalation.

Executive summary

A high severity privilege escalation vulnerability exists in Microsoft Dynamics OmniChannel SDK Storage Containers that allows unauthenticated network attackers to compromise system integrity.

Vulnerability

This flaw is caused by improper authorization (CWE-285) within the storage container component, which fails to validate user permissions correctly. An unauthenticated attacker can leverage this weakness to gain elevated privileges over the network.

Business impact

With a CVSS score of 8.8, this vulnerability poses a significant risk to organizational security. Successful exploitation could lead to full unauthorized access, potential data exfiltration, or the ability for an attacker to perform administrative actions, resulting in severe reputational damage and operational disruption.

Remediation

Immediate Action: Review the official Microsoft Security Update Guide for CVE-2025-64655 and apply all recommended patches or configuration changes provided by the vendor.

Proactive Monitoring: Monitor network access logs for suspicious traffic patterns originating from unauthorized sources directed at Dynamics OmniChannel storage interfaces.

Compensating Controls: Implement strict network segmentation and access control lists to limit exposure of the affected storage containers to only necessary internal systems.

Exploitation status

Public Exploit Available: No — exploit_available (false).

Analyst recommendation

The potential for privilege escalation makes this a high priority for security teams. Organizations should immediately verify their versions of Microsoft Dynamics OmniChannel SDK against the vendor advisory and deploy available security updates to neutralize this threat vector.

More Microsoft CVEs

Sources