services / Azure / Virtual network subnet
A subnet is a segment of a virtual network's address space, used to isolate groups of resources and as the attachment point for NSGs, route tables, service endpoints, and delegated services.
Subnets are the unit of network segmentation within a VNet; control-plane privileges on it — altering address ranges, NSG/route-table associations, delegations, or attaching unauthorized resources into it — can enable significant privilege escalation via lateral network access (per the CRITICAL definition in services/README.md).
Microsoft.Network/virtualNetworks/subnets/write
Creating or updating a subnet lets an attacker change its address range, detach or swap its NSG/route-table association, or add service endpoints/delegations, weakening the isolation the subnet was meant to enforce.
Risks
Scope: CRITICAL
This privilege may grant access to sensitive data from a significant fraction of organizational functions, allow interruption of critical organizational services, or its exploit could lead to significant privilege escalation.
Links
Contributed by P0 Security