CVE-2025-47988
published 2025-07-08CVE-2025-47988: Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthorized attacker to execute code over an adjacent network.
PriorityP344high7.5CVSS 3.1
AVAACHPRNUINSUCHIHAH
EPSS
0.84%
53.5th percentile
Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthorized attacker to execute code over an adjacent network.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | azure_monitor | >= 1.0.0 < 1.35.1 | 1.35.1 |
| microsoft | azure_monitor_agent | < 1.35.1 | 1.35.1 |
| msrc | azure_monitor_agent | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_msrc7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Microsoft
Azure Monitor Agent Remote Code Execution Vulnerability
vendor_msrc·2025-07-08·CVSS 7.5
CVE-2025-47988 [HIGH] CWE-94 Azure Monitor Agent Remote Code Execution Vulnerability
Azure Monitor Agent Remote Code Execution Vulnerability
Description: Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthorized attacker to execute code over an adjacent network.
FAQ: What actions do customers need to take to protect themselves from this vulnerability?
Customers who have disabled Automatic Extension Upgrades or would like to upgrade an extension immediately must manually update their Azure Monitor Agent to the latest version. For more information on how to perform a manual update, see Manage Azure Monitor Agent.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation depends on the vulnerable troubleshooting script in the Azure monitoring age
GHSA
GHSA-fvm8-p9v4-fpvh: Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthorized attacker to execute code over an adjacent netw
ghsa_unreviewed·2025-07-08
CVE-2025-47988 [HIGH] CWE-94 GHSA-fvm8-p9v4-fpvh: Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthorized attacker to execute code over an adjacent netw
Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthorized attacker to execute code over an adjacent network.
No detection rules found.
No public exploits indexed.
2025-07-08
Published