CVE Vulnerabilities

CVE-2025-24986

Improper Isolation or Compartmentalization

Published: Mar 11, 2025 | Modified: Jul 10, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Improper isolation or compartmentalization in Azure PromptFlow allows an unauthorized attacker to execute code over a network.

Weakness

The product does not properly compartmentalize or isolate functionality, processes, or resources that require different privilege levels, rights, or permissions.

Affected Software

Name Vendor Start Version End Version
Azure_promptflow_core Microsoft * 1.17.2 (excluding)
Azure_promptflow_tools Microsoft * 1.6.0 (excluding)

Potential Mitigations

References