CVE-2025-54914 is a Critical elevation of privilege vulnerability affecting Microsoft Azure Networking services. Publicly available information identifies the weakness as CWE-284 (Improper Access Control), indicating a failure in access control enforcement within the Azure Networking service that could allow an attacker to obtain permissions beyond those intended. Microsoft assigned the issue a CVSS 3.1 base score of 10.0 with vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H, which indicates network-based exploitation, low attack complexity, no privileges required, and no user interaction. Microsoft has not publicly disclosed detailed technical root-cause information, vulnerable components/functions, affected version ranges, or exploitation steps. Microsoft stated the issue was fully mitigated at the service level before or at disclosure.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository is a comprehensive exploit toolkit targeting CVE-2025-54914, a vulnerability in Microsoft Azure's networking route management. The main exploit (exploit.py) allows an attacker to create or delete custom routes in Azure virtual networks and subnets by interacting with the Azure Management API (https://management.azure.com). The exploit supports both single and multi-target operations, with targets specified via command-line arguments or a JSON configuration file (e.g., targets_sample.json). It includes advanced features such as evasion (random delays, user agent rotation), persistence (scheduled tasks, continuous monitoring), and detailed reporting. The utility script (exploit_utils.py) provides target discovery, configuration management, and vulnerability analysis, automating the identification of exploitable Azure resources. The exploit is operational, requiring valid Azure credentials and network access to the Azure API. The repository is structured for both offensive security testing and research, with clear separation between exploitation, utilities, and configuration data.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical privilege escalation vulnerability in Azure Networking referenced as part of Microsoft's 2025 Azure security history.
An Azure Networking elevation of privilege vulnerability mentioned only as part of Microsoft's 2025 Azure security history.
A critical privilege escalation vulnerability in Azure Networking with a CVSS score of 10.0. No customer action is required as it is managed by Microsoft in the cloud.
A critical elevation of privilege vulnerability in Azure Networking, with a high CVSS score, potentially allowing attackers to gain elevated privileges in Azure environments.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.