Improper Access Control Vulnerability in Azure Monitor Agent by Microsoft
CVE-2025-59494

7.8HIGH

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
14 October 2025

What is CVE-2025-59494?

The Azure Monitor Agent is susceptible to an improper access control vulnerability, enabling an authorized attacker to elevate their local privileges. This flaw may allow malicious users to gain unauthorized access to sensitive system functionalities, increasing the risk of further exploitation within the affected environment. Organizations utilizing the Azure Monitor Agent should evaluate their systems to mitigate this security risk.

Affected Version(s)

Azure Monitor Unknown 1.0.0 < 1.38.1.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.