CVE-2025-29972

Published May 8, 2025

Last updated 24 days ago

Overview

Description
Server-side request forgery (ssrf) in Azure Storage Resource Provider allows an authorized attacker to perform spoofing over a network.
Source
secure@microsoft.com
NVD status
Modified
CNA Tags
exclusively-hosted-service
Products
azure_storage_resource_provider

Risk scores

CVSS 3.1

Type
Primary
Base score
9.8
Impact score
5.9
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity
CRITICAL

Weaknesses

secure@microsoft.com
CWE-918

Social media

Hype score
Not currently trending
  1. #後で読む 用メモです→ [レポート]クラウド全体への汚染拡大:SSRFの連鎖によるAzureテナント侵害 (CVE-2025-29972) - CODE BLUE 2025 #codeblue_jp #codeblue2025 https://t.co/QWeYB9YjNe

    @TommiyTw

    19 Nov 2025

    14 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  2. [レポート]クラウド全体への汚染拡大:SSRFの連鎖によるAzureテナント侵害 (CVE-2025-29972) - CODE BLUE 2025 #codeblue_jp #codeblue2025 | DevelopersIO https://t.co/TwVYHS9gmG

    @yokatsuki

    19 Nov 2025

    82 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  3. すげー攻撃の流れだった [レポート]クラウド全体への汚染拡大:SSRFの連鎖によるAzureテナント侵害 (CVE-2025-29972) - CODE BLUE 2025 #codeblue_jp #codeblue2025 https://t.co/4mVR0LHvmA #DevelopersIO

    @ke_ni_

    19 Nov 2025

    629 Impressions

    1 Retweet

    4 Likes

    2 Bookmarks

    0 Replies

    0 Quotes

  4. > 新しいDNSリバインディング技術 クラウド全体への汚染拡大:SSRFの連鎖によるAzureテナント侵害 (CVE-2025-29972) | Time Table – 世界トップクラスの専門家による情報セキュリティ国際会議「CODE BLUE(コードブル

    @shibanyan_1

    22 Sept 2025

    529 Impressions

    2 Retweets

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. ماکروسافت به تازگی برای ۴ آسیب پذیری که برای سرویس Azure cloud و Power Apps منتشر شده است ، پچ لازم را ارائه داده است. این آسیب پذیری ها دارای کدهای شناسایی CVE-2025-29813 و

    @AmirHossein_sec

    18 May 2025

    32 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  6. ⚠️Actualizaciones mensuales de Microsoft ❗CVE-2025-29813 ❗CVE-2025-29972 ❗CVE-2025-29827 ❗CVE-2025-47733 ➡️Más info: https://t.co/bB03utcmcw https://t.co/uwmTwujltX

    @CERTpy

    16 May 2025

    116 Impressions

    2 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. Vulnerabilidades críticas de seguridad en la nube de Microsoft CVE-2025-29813 Azure DevOps Elevation of Privilege CVE-2025-29972 Azure Storage Resource Provider Spoofing CVE-2025-29827 Azure Automation Elevation of Privilege https://t.co/fSALC0mUZN https://t.co/V3lGgKu0kG

    @elhackernet

    13 May 2025

    2341 Impressions

    10 Retweets

    16 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  8. 🚨 CVE-2025-29972 ⚠️🔴 CRITICAL (9.9) 🏢 Microsoft - Azure Storage Resource Provider (SRP) 🏗️ N/A 🔗 https://t.co/m3mcZG4Q33 #CyberCron #VulnAlert #InfoSec https://t.co/2oRRUBGwY4

    @cybercronai

    9 May 2025

    23 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

Configurations

References

Sources include official advisories and independent security research.