CVE-2025-24513Patch

MEDIUMCVSS 4.8 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

A security issue was discovered in ingress-nginx https://github.com/kubernetes/ingress-nginx where attacker-provided data are included in a filename by the ingress-nginx Admission Controller feature, resulting in directory traversal within the container. This could result in denial of service, or when combined with other vulnerabilities, limited disclosure of Secret objects from the cluster.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-04-16: 1Active Exploitation · 2026-04-16: 1Patch / Workaround · 2026-04-16: 1Technical Details · 2026-04-16: 104-16
Signal classification1 categories
Patch
1100.0%
Referenced assets7 URLs
Full discourse1 post
  • Yoko Hasebe (長谷部洋子 岩国市)@yokotf4yur
    Patch

    https://youtube.com/shorts/6BSWMZkihUI?si=YmepQEcWwfKlNBnJ ## ✅ 確認済み:最新 Azure 脆弱性・CVE 情報(2025〜2026年) ### 🔴 最重要:CVE-2025-55241(Entra ID) **CVSS 10.0 / Critical** Microsoft Entra IDのトークン検証不備により、攻撃者が任意のユーザー(グローバル管理者を含む)をすべてのテナントにわたって偽装できる脆弱性。発見者はセキュリティ研究者 Dirk-Jan Mollema(2025年7月14日報告)で、Microsoftは3日後の7月17日に修正を完了。顧客側の対応は不要。野生での悪用は確認されていない。 [The Hacker News](https://thehackernews.com/2025/09/microsoft-patches-critical-entra-id.html) 技術的な原因は、レガシーAzure AD Graph APIのトークン検証の欠陥。攻撃者が自テナントで取得した「Actorトークン」を他テナントに使い回すことで、MFAや条件付きアクセスポリシーをバイパスしてテナント全体を侵害できる状態だった。 [Uvcyber](https://www.uvcyber.com/resources/reports/threat-advisory-azure-entra-id-vulnerability) **対応アクション:** - Azure AD Graph API(2025年8月31日に廃止済み)への依存を排除 - Microsoft Graphへ移行 - PIM(Privileged Identity Management)の導入 --- ### 🔴 CVE-2026-20965(Windows Admin Center) **High / テナント全体への横断アクセス** Windows Admin Center の Azure SSO実装に高深刻度の脆弱性。不正なトークン検証により、Azure VMおよびArc接続システム全体への不正アクセスが可能。Microsoftは2026年1月13日リリースのv0.70.00で修正。それ以前のバージョンは依然として脆弱。 [Gopher](https://www.gopher.security/news/critical-azure-entra-id-vulnerability-allows-tenant-wide-compromise) --- ### 🟠 AKS(Azure Kubernetes Service)関連 CVE 2025年3月、Kubernetes nginx ingress controllerに複数の脆弱性が開示された:CVE-2025-1974(Critical)、CVE-2025-1098(High)、CVE-2025-1097(High)、CVE-2025-24514(High)、CVE-2025-24513(Medium)。ingress-nginxを使用しているクラスターが対象。AKSのマネージドアドオンはパッチ済みだが、独自導入の場合はv1.11.5またはv1.12.1へのアップデートが必要。 [Microsoft Learn](https://learn.microsoft.com/en-us/azure/aks/security-bulletins/overview) また、runcに関するCVE-2025-31133、CVE-2025-52565、CVE-2025-52881も開示済み。新しいノードイメージがロールアウトされている。 [Microsoft Learn](https://learn.microsoft.com/en-us/azure/aks/security-bulletins/overview) --- ### 🟠 Azure Bastion CVE-2025-49752 **CVSS 10.0 / Critical** Azure BastionにCVE-2025-49752として追跡される重大な認証バイパス脆弱性。単一のネットワークリクエストでAzure VMへの管理者アクセスを取得できる可能性がある。CWE-294(認証バイパス)に分類され、事前認証・ユーザー操作なしでリモート悪用が可能。 [Zeropath](https://zeropath.com/blog/azure-bastion-cve-2025-49752) --- ### 🟡 2026年4月 Patch Tuesday(最新・4月16日) Microsoftは2026年4月のPatch Tuesdayで163件のCVEを修正。うち8件がCritical評価。CVE-2026-32201はSharePointのゼロデイで実際に悪用された。 [Tenable®](https://www.tenable.com/blog/microsofts-april-2026-patch-tuesday-addresses-163-cves-cve-2026-32201) 主なCVE: - **CVE-2026-33826**:Windows Active Directory RCE(Critical、CVSS 8.0) - **CVE-2026-33824**:Windows IKE RCE(Critical、CVSS 9.8、未認証攻撃可能) - **CVE-2026-33825**:Microsoft Defender 権限昇格(Important) --- ### 📋 信頼性まとめ | CVE | サービス | 深刻度 | 確認状況 | |-----|---------|--------|---------| | CVE-2025-55241 | Entra ID | CVSS 10.0 | ✅ 実在 | | CVE-2025-49752 | Azure Bastion | CVSS 10.0 | ✅ 実在 | | CVE-2026-20965 | Windows Admin Center | High | ✅ 実在 | | CVE-2025-1974 | AKS nginx | Critical | ✅ 実在 | | CVE-2026-32201 | SharePoint | 実悪用確認 | ✅ 実在 | --- 特定のCVEの詳細や、対策方法について知りたい場合はお知らせください!←Claude

    Post summary

    The post lists several critical Azure and Windows CVEs, provides technical details, confirms patch releases by Microsoft, notes real exploitation for CVE‑2026‑32201, and outlines remediation steps.

    00000231

Explore more