Here is what you should know about a critical CVSS 10 vulnerability (CVE-2025-54914) in Azure
12 Sep 2025
A critical vulnerability, CVE-2025-54914, has been discovered in Microsoft’s Azure Networking services that could potentially affect organizations that have deployed Azure for their operations.
Let us take a closer look at the vulnerability and all the probable threats posed by it.
An overview of the vulnerability(CVE-2025-54914)
The vulnerability is an elevation of privilege vulnerability with a CVSS score of 10, indicating that it poses a severe risk to organizations by giving attackers complete control of Azure infrastructure without any dependence on user interaction. It was discovered on 4th September and classified under CWE-284, which is Improper Access Control. Microsoft has already released an advisory regarding the vulnerability.
Systems and versions affected by the vulnerability
The vulnerability impacts Microsoft Azure Networking services. However, the exact versions affected have not yet been published.
Threat posed by the vulnerability
A lot of organizations have deployed Azure as their networking setup. Therefore, a lot of load balancers, virtual machines, and subnet traffic depend on Azure’s stack.
By exploiting the vulnerability, an attacker can pose multiple threats to an organization. An attacker can:
- Gain complete control over Azure network resources, including all the existing routing tables, subnets, and virtual NICs.
- Engage in lateral movement on cloud and hybrid environments: across the services that depend on the Azure network.
- Alter data flow: by injecting malicious traffic or modifying routing policies.
- Remotely execute an attack without depending on user action.
- Engage in privilege escalation under certain conditions.
As Microsoft has already resolved the issue, along with 80 other security flaws, in its Patch Tuesday, it requires no action from the users.
How SharkStriker helps secure cloud ?
As cybercriminals keep looking for new methods, tactics, and tools to make their campaigns and attacks more effective, organizations face increased pressure to keep up.
They face risks like:
- Targeted attacks(especially MSPs)
- Misconfigurations
- Ransomware
- Insecure APIs
- Third-party vulnerabilities
- Poor identity & access management practices
- Rising risk of shadow IT
- Insider threats
- Non-compliance
Securing the cloud has become one of the top worries for CISOs and owners. In a recent Fortinet research, it was found that over 64% of organizations reported that they are losing confidence in their ability to handle real-time threat detection over the cloud, with 92% of them reporting being worried about cloud security risks.
SharkStriker helps organizations secure their cloud-based operations, workload, and data by offering them a dedicated team to identify risks across their cloud environments and configure, assess, and manage their cloud security stack.
Through a purpose-built, multi-tenant, vendor-agnostic security platform, STRIEGO, organizations can unify visibility and control with existing cloud security solutions across different vendors. It offers a built-in machine learning powered detection engine that automatically monitors cloud infrastructure for threats, responding to risks and threats based on playbooks tailored by our security team.
Learn more about some [network security best practices for cloud computing]