Heap-based Buffer Overflow in Azure Monitor Agent from Microsoft
CVE-2025-59504

7.3HIGH

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
11 November 2025

What is CVE-2025-59504?

A heap-based buffer overflow vulnerability exists in the Azure Monitor Agent, enabling unauthorized attackers to execute arbitrary code locally. Successful exploitation could lead to severe impacts on system integrity and availability, allowing attackers to manipulate data or disrupt services. Organizations using the Azure Monitor Agent should apply necessary patches and updates provided by Microsoft to mitigate this risk.

Affected Version(s)

Azure Monitor Unknown 1.0.0

References

CVSS V3.1

Score:
7.3
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.