CVE-2025-64676

7.2

Microsoft · Microsoft Purview

A path traversal and code injection vulnerability in Microsoft Purview allows an authorized attacker to execute arbitrary code over a network.

Executive summary

A path traversal vulnerability in Microsoft Purview permits authorized attackers to achieve remote code execution, posing a significant risk to data integrity and system control.

Vulnerability

This vulnerability involves a path traversal flaw, specifically utilizing the pattern .../...//, which enables code injection. The vulnerability requires the attacker to possess high privileges to successfully execute code over the network.

Business impact

The ability for an authorized attacker to execute arbitrary code via path traversal represents a critical security failure, potentially leading to total system compromise. With a CVSS score of 7.2, this high severity flaw could facilitate unauthorized data access, lateral movement within the network, and complete loss of confidentiality, integrity, and availability for the affected Purview instance.

Remediation

Immediate Action: Apply all security updates provided by Microsoft in the official update guide as soon as they are released.

Proactive Monitoring: Review access logs for anomalous file path requests or unexpected execution patterns that match the path traversal signature.

Compensating Controls: Implement strict access control lists to ensure only authorized users can interact with sensitive Purview components, limiting the potential reach of compromised accounts.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit in the available data.

Analyst recommendation

Given the potential for remote code execution, organizations should treat this vulnerability with high priority. Administrators must monitor the Microsoft Security Response Center update guide for the release of patches and verify that all instances of Microsoft Purview are updated immediately upon availability to prevent exploitation by privileged actors.

More Microsoft CVEs

Sources