Description
Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthorized attacker to execute code over an adjacent network.
CVSS vector
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 1.6 | Impact: 5.9Attack Vector: Adjacent
Complexity: High
Privileges: None
User Interaction: None
Scope: Unchanged
Confidentiality: High
Integrity: High
Availability: High
Affected Packages2 packages
🔴Vulnerability Details
2CVEListAzure Monitor Agent Remote Code Execution Vulnerability↗2025-07-08 ▶ GHSAGHSA-fvm8-p9v4-fpvh: Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthorized attacker to execute code over an adjacent netw↗2025-07-08 ▶ 📋Vendor Advisories
1MicrosoftAzure Monitor Agent Remote Code Execution Vulnerability↗2025-07-08 ▶