CVE-2025-59503: Azure Compute Resource Provider Elevation of Privilege Vulnerability
Published Oct 23, 2025
·Updated
Azure Compute Resource Provider Elevation of Privilege Vulnerability
Other sources
Server-side request forgery (ssrf) in Azure Compute Gallery allows an unauthorized attacker to elevate privileges over a network.
— Microsoft
Affected Software
2 affected components
Microsoft Azure Compute Resource Provider
Microsoft Azure Compute Resource Provider
Event History
Oct 23, 2025
CVE Published
via Microsoft·07:00 AM
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeaknessAffected Software
Updated
via Microsoft·07:00 AM
Description
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·09:18 PM
Data Sourced
via MITRE·09:18 PM
DescriptionSeverity
Data Sourced
via NVD·10:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-59503?
CVE-2025-59503 is classified as a high-severity vulnerability due to its potential for privilege escalation.
2
How do I fix CVE-2025-59503?
To mitigate CVE-2025-59503, ensure that all Azure Compute Resource Provider services are updated to the latest security patches.
3
Who is affected by CVE-2025-59503?
Organizations using Microsoft Azure Compute Resource Provider are affected by CVE-2025-59503.
4
What type of vulnerability is CVE-2025-59503?
CVE-2025-59503 is a server-side request forgery (SSRF) vulnerability that allows for privilege elevation.
5
Can CVE-2025-59503 be exploited remotely?
Yes, CVE-2025-59503 can be exploited remotely by an authenticated attacker to elevate privileges.