External risk intelligence

Azure Compute Gallery SSRF Allows Privilege Escalation

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2025-59503

Azure Compute Gallery is an internal cloud resource provider service rather than a public-facing web or gateway service. While it operates over a network, it is typically managed and accessed within the Azure infrastructure and not directly exposed as an internet-facing endpoint for the general public.

Server-Side Request Forgery

Microsoft Azure Compute Resource Provider

Halo Surface Signal: 3 out of 5 — possibly public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in Microsoft Azure Compute Gallery, a service for managing virtual machine images and related artifacts. The flaw, identified as a server-side request forgery, could allow an unauthorized attacker to gain elevated privileges across a network. The primary concern is confirming the relevance and exposure of this internal cloud resource provider service to our specific environment.

  • Attackers can potentially gain higher access.
  • It affects how we manage cloud resources.
  • Assess exposure and internal impact.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by sending a specially crafted request to the Azure Compute Gallery over a network. This could allow them to bypass authentication and potentially elevate their privileges within the Azure environment.

  • Unauthenticated network access required.
  • Triggered by sending a malicious request.
  • Potential for privilege escalation.

Live Threat

Current exploitation, exposure, and threat context

Azure Compute Gallery's server-side request forgery vulnerability could allow an attacker to make unauthorized requests to internal Azure resources over a network. This exposure is possible when the service is configured to process user-supplied input in requests.

  • Internal Azure resource access.
  • Unsanitized user input in requests.
  • Potential unauthorized access to internal services.

Operational Fix

Recommended remediation, mitigation, and detection steps

This Server-Side Request Forgery vulnerability in Azure Compute Gallery impacts the Microsoft Azure Compute Resource Provider. Responsibility for addressing this likely falls to the cloud platform or infrastructure team managing Azure services, in coordination with the security team to understand the exposure and vendor management for coordinating with Microsoft. The first practical step is to identify all instances of the Azure Compute Gallery, assess their network reachability, determine business criticality, and confirm the accountable owner before planning remediation.

  • Cloud platform and security teams own remediation.
  • Verify Azure Compute Gallery instances and reachability.
  • Plan vendor-coordinated remediation based on risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the Azure Compute Resource Provider?

It is a foundational Microsoft service component that enables the management of virtual machine images, galleries, and related artifacts within the Azure cloud ecosystem. Developers and infrastructure teams use this service to store, share, and organize machine images to ensure consistent deployments across their cloud environments.

How does this CVE-2025-59503 vulnerability work?

This flaw is classified as a Server-Side Request Forgery (CWE-918). In simple terms, it means the service can be tricked into making unintended requests to other internal locations. Because the service fails to properly validate input, an attacker can manipulate it to act on their behalf, potentially gaining elevated access or unauthorized privileges within the network.

What triggers this SSRF vulnerability?

The vulnerability is triggered when an attacker sends a specially crafted, malicious request to the Azure Compute Gallery service. Importantly, this issue arises from how the service handles provided input; it is not triggered by standard, legitimate management tasks or routine administrative operations performed by authorized users.

Is this CVE-2025-59503 relevant to my public apps?

According to Halo Surface Signal, this service is typically an internal cloud resource provider rather than a public-facing web gateway. While it operates over a network, it is generally managed within the private Azure infrastructure. Therefore, it is less likely to be directly exposed to the open internet compared to traditional public-facing web applications.

What should I do if I use Azure Compute Gallery?

Your first step is to locate all instances of the Azure Compute Gallery used in your environment. Collaborate with your cloud infrastructure and security teams to verify their network reachability and determine who owns each instance. Once identified, maintain close communication with Microsoft to track official updates and guidance for your specific configurations.

References