External Control of File Path Vulnerability in Azure Container Instances by Microsoft
CVE-2025-59292

8.2HIGH

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
14 October 2025

What is CVE-2025-59292?

A vulnerability in Azure Container Instances enables an authorized attacker to manipulate file paths, potentially allowing for local privilege escalation. This issue arises from insufficient input validation, which can be exploited to execute unauthorized actions within the environment.

Affected Version(s)

Azure Compute Gallery Unknown

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
High
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.