Server-Side Request Forgery Vulnerability in Azure Compute Gallery by Microsoft
CVE-2025-59503

9.9CRITICAL

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
23 October 2025

What is CVE-2025-59503?

A vulnerability exists in Azure Compute Gallery that allows an authorized attacker to perform server-side request forgery (SSRF). This security issue can enable attackers to leverage unauthorized privileges over a network, facilitating broader access within affected environments. It's essential to implement security measures to address this risk and ensure system integrity.

Affected Version(s)

Azure Compute Resource Provider Unknown

References

CVSS V3.1

Score:
9.9
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-59503 : Server-Side Request Forgery Vulnerability in Azure Compute Gallery by Microsoft