CRITICAL 9.8 Microsoft

CVE-2025-47966

Power Automate Elevation of Privilege Vulnerability

Microsoft Security Update 2025-Jun: Power Automate Elevation of Privilege Vulnerability

Affected Products

References

Published: 2025-06-10 · Source: Microsoft · Feed updated: 2026-08-15
This critical severity vulnerability with a CVSS score of 9.8 was published on 2025-06-10 via Microsoft. Affected: Power Automate for Desktop.

Risk Timeline

CVE Disclosed2025-06-10 · 431 days ago

Remediation Resources

Related Vulnerabilities

CVETitleSeverityCVSS
CVE-2026-58647Microsoft PowerBI Report Server Spoofing VulnerabilityHIGH8.0
CVE-2026-40374Microsoft Power Automate Desktop Information Disclosure VulnerabilityMEDIUM6.5
vulnfeed aggregates 10939 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.