<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Cve-2025-5791 on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/cve-2025-5791/</link><description>Recent content in Cve-2025-5791 on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Thu, 20 Jun 2024 08:40:10 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/cve-2025-5791/index.xml" rel="self" type="application/rss+xml"/><item><title>CVE-2025-5791: Azure Root User Group Listing Flaw</title><link>https://zxcloudsecurity.co.uk/posts/cve-2025-5791-azure-root-group-listing-information-disclosure/</link><pubDate>Sat, 20 Jun 2026 08:40:10 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/cve-2025-5791-azure-root-group-listing-information-disclosure/</guid><description>CVE-2025-5791 causes &amp;#39;root&amp;#39; to be incorrectly appended to Azure group listings, risking information disclosure and potential reconnaissance by attackers.</description><content:encoded><![CDATA[<p>🟡 <strong>Medium</strong>  |  <strong>Source:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-5791">Microsoft Security Response Center</a></p>
<hr>
<p>CVE-2025-5791 is a vulnerability in Azure where the &lsquo;root&rsquo; user is incorrectly appended to group listings, potentially exposing unintended group membership information. This could allow an attacker or unprivileged user to enumerate group memberships they should not be aware of, aiding reconnaissance. While the direct impact may appear limited, information disclosure in identity and access contexts can facilitate privilege escalation attempts.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Review your Azure environments for any reliance on group membership confidentiality as a security control, and monitor for unusual group enumeration activity. Apply any available patches or mitigations from Microsoft promptly, and audit who can query group listings within your tenants.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-5791">CVE-2025-5791 Users: <code>root</code> appended to group listings</a></p>
]]></content:encoded></item></channel></rss>