---
cve: "CVE-2025-65037"
severity: "CRITICAL"
cvss: 10.0
epss: "1%"
vendor: "Microsoft"
kev: false
exploited: false
published: "2025-12-18 22:16:01"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-10-10T14:15:57+02:00"
---

# CVE-2025-65037

> 10.0 CRITICAL

## Beschreibung

Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to execute code over a network.

## CISA-Anreicherung (vulnrichment/ADP)

- CISA-SSVC (Coordinator, v2.0.3):
  - Exploitation: **none**
  - Automatable: **yes**
  - Technical Impact: **total**

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Verändert | bad |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## BSI-Hinweise (deutsch)

- [Microsoft Azure Komponenten: Mehrere Schwachstellen](https://wid.cert-bund.de/portal/wid/sicherheitshinweis/WID-SEC-W-2025-2890) — _BSI-Einstufung: hoch_
  Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Microsoft Azure Cosmos DB und anderen Microsoft Azure Komponenten ausnutzen, um seine Privilegien zu erweitern, beliebigen Code auszuführen und um einen Cross-Site Scripting Angriff zu starten.

## Referenzen

- <https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-65037>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/sicherheitsluecken/cve-2025-65037/) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI WID (CSAF)_
