Skip to main content

CVE-2025-30389

8.7
HIGHCVSS v3.1 Base Score
0.41%
LOW RiskEPSS (62nd percentile)

Improper authorization in Azure Bot Framework SDK allows an unauthorized attacker to elevate privileges over a network.

Published: 4/30/2025
Modified: 5/12/2025
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

8.7HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N

EPSS Score (Exploitation Probability)

0.41%LOW Exploitation Risk
62nd percentile

This vulnerability has a 0.41% probability of being exploited in the next 30 days, ranking higher than 62% of all scored CVEs.

CWE Classification

Related Vulnerabilities

Same Weakness Type(CWE-285)

CVE-2026-0574MEDIUM 6.3

A weakness has been identified in yeqifu warehouse up to aaf29962ba407d22d991781de28796ee7b4670e4. This affects the function saveUserRole of the file warehouse\src\main\java\com\yeqifu\sys\controller\UserController.java of the component Request Handler. This manipulation causes improper authorization. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified.

1/4/2026
CVE-2025-65041CRITICAL 10

Improper authorization in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.

12/18/2025
CVE-2025-66301CRITICAL 9.6

Grav is a file-based Web platform. Prior to 1.8.0-beta.27, due to improper authorization checks when modifying critical fields on a POST request to /admin/pages/{page_name}, an editor with only permissions to change basic content on the form is now able to change the functioning of the form through modifying the content of the data[_json][header][form] which is the YAML frontmatter which includes the process section which dictates what happens after a user submits the form which include some important actions that could lead to further vulnerabilities. This vulnerability is fixed in 1.8.0-beta.27.

12/1/2025
CVE-2025-13806HIGH 7.3

A security vulnerability has been detected in nutzam NutzBoot up to 2.6.0-SNAPSHOT. This impacts an unknown function of the file nutzboot-demo/nutzboot-demo-simple/nutzboot-demo-simple-web3j/src/main/java/io/nutz/demo/simple/module/EthModule.java of the component Transaction API. The manipulation of the argument from/to/wei leads to improper authorization. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used.

12/1/2025
CVE-2025-64655HIGH 8.8

Improper authorization in Dynamics OmniChannel SDK Storage Containers allows an unauthorized attacker to elevate privileges over a network.

11/20/2025

Similar SeverityHIGH