CVE-2025-65037 Azure Container Apps Remote Code Execution Vulnerability
Published December 19, 2025
Improper control of generation of code (‘code injection’) in Azure Container Apps allows an unauthorized attacker to execute code over a network.
Published December 19, 2025
Improper control of generation of code (‘code injection’) in Azure Container Apps allows an unauthorized attacker to execute code over a network.
Published December 19, 2025
Improper authorization in Microsoft Partner Center allows an unauthorized attacker to elevate privileges over a network.
Published December 19, 2025
Information published.
Published December 19, 2025
Improper neutralization of input during web page generation (‘cross-site scripting’) in Azure Cosmos DB allows an unauthorized attacker to perform spoofing over a network.
Published December 19, 2025
Improper neutralization of input during web page generation (‘cross-site scripting’) in Office Out-of-Box Experience allows an unauthorized attacker to perform spoofing over a network.
Published December 19, 2025
Information published.
Published December 19, 2025
This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see [Google Chrome Releases](https://chromereleases.googleblog.com/2024 ) for more information.
Published December 19, 2025
Information published.
Published December 19, 2025
‘…/…//’ in Microsoft Purview allows an authorized attacker to execute code over a network.
Published December 19, 2025
Information published.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.