External Control of File Path Vulnerability in Azure Container Instances by Microsoft
CVE-2025-59291

8.2HIGH

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
14 October 2025

What is CVE-2025-59291?

The vulnerability in Azure Container Instances facilitates an attack where an authorized user can manipulate file names or paths, potentially leading to unauthorized privilege escalation locally. This flaw underscores the importance of strict controls and monitoring within cloud container environments to mitigate the risk of exploitation.

Affected Version(s)

Azure Compute Gallery Unknown

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.