Permissive list of allowed inputs in Microsoft Purview allows an authorized attacker to elevate privileges over a network.
The product implements a protection mechanism that relies on a list of inputs (or properties of inputs) that are explicitly allowed by policy because the inputs are assumed to be safe, but the list is too permissive - that is, it allows an input that is unsafe, leading to resultant weaknesses.
Link | Tags |
---|---|
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53762 | vendor advisory |