CVE-2025-29972 is a critical server-side request forgery (SSRF) vulnerability affecting Microsoft Azure Storage Resource Provider. An unauthenticated attacker can exploit this flaw over a network to perform spoofing, leading to high impacts on confidentiality, integrity, and availability. While not yet in the KEV catalog, its high CVSS score of 9.8 and FAUCET Risk Score of 93/100 indicate severe potential. Although public exploit code is currently unavailable, its mention in a recent Patch Tuesday article and community discussions suggest growing awareness.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:microsoft:azure_storage_resource_provider:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.