CVE-2025-59504
published 2025-11-11CVE-2025-59504: Heap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code locally.
PriorityP343high7.3CVSS 3.1
AVLACLPRNUINSUCLILAH
EPSS
0.32%
24.0th percentile
Heap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code locally.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | azure_monitor | >= 1.0.0 < v1.37.1 | v1.37.1 |
| microsoft | azure_monitor_agent | < 1.37.1 | 1.37.1 |
| msrc | azure_monitor | — | — |
CVSS provenance
nvdv3.17.3HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:H
vendor_msrc7.3HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2575-3228-j966: Heap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code locally
ghsa_unreviewed·2025-11-11
CVE-2025-59504 [HIGH] CWE-122 GHSA-2575-3228-j966: Heap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code locally
Heap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code locally.
Microsoft
Azure Monitor Agent Remote Code Execution Vulnerability
vendor_msrc·2025-11-11·CVSS 7.3
CVE-2025-59504 [HIGH] CWE-122 Azure Monitor Agent Remote Code Execution Vulnerability
Azure Monitor Agent Remote Code Execution Vulnerability
Description: Heap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code locally.
FAQ: How can I tell if this issue affects me, and what steps should I take to stay protected?
If you have Azure Monitor Agent extension version 1.37.0 or below you are affected. To protect your device, please upgrade to version 1.37.1 and above.
FAQ: According to the CVSS metrics, successful exploitation of this vulnerability could lead to some loss of confidentiality (C:L) and integrity (I:L), and major loss of availability (A:H). What does that mean for this vulnerability?
This means for the vulnerability, while data exposure and tampering are possible, the most significant impact is on system availability—explo
No detection rules found.
No public exploits indexed.
Bleepingcomputer
Microsoft November 2025 Patch Tuesday fixes 1 zero-day, 63 flaws
blogs_bleepingcomputer·2025-11-11·CVSS 7.0
[HIGH] Microsoft November 2025 Patch Tuesday fixes 1 zero-day, 63 flaws
## Microsoft November 2025 Patch Tuesday fixes 1 zero-day, 63 flaws
## Lawrence Abrams
29 Elevation of Privilege Vulnerabilities
2 Security Feature Bypass Vulnerabilities
16 Remote Code Execution Vulnerabilities
11 Information Disclosure Vulnerabilities
3 Denial of Service Vulnerabilities
2 Spoofing Vulnerabilities
When BleepingComputer reports on the Patch Tuesday security updates, we only count those released today by Microsoft. Therefore, the number of flaws does not include Microsoft Edge and Mariner vulnerabilities fixed earlier this month.
Today is also the first extended security update (ESU) for Windows 10, so if you are still utilizing the unsupported operating system, it is strongly advised that you upgrade to Windows 11 or enroll in the ESU program .
For those who are
Wiz
CVE-2025-62550 Impact, Exploitability, and Mitigation Steps | Wiz
blogs_wiz·CVSS 7.5
CVE-2025-62550 [HIGH] CVE-2025-62550 Impact, Exploitability, and Mitigation Steps | Wiz
## CVE-2025-62550 :
Azure Monitor agent vulnerability analysis and mitigation
Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network.
Source : NVD
## 8.8
Score
Published December 9, 2025
Severity HIGH
CNA Score 8.8
Affected Technologies
Azure Monitor agent
Has Public Exploit No
Has CISA KEV Exploit No
CISA KEV Release Date N/A
CISA KEV Due Date N/A
Exploitation Probability Percentile (EPSS) 28.2
Exploitation Probability (EPSS) 0.1
Affected packages and libraries
cpe:2.3:a:microsoft:azure_monitor_agent
Sources
Linux Severity HIGH Has Fix Added at: Dec 11, 2025
Windows Severity HIGH Has Fix Added at: Dec 11, 2025
Linux Severity HIGH Has Fix Added at: Dec 12, 2025
Windows Severity HIGH Has Fix Added at: Dec 12, 2025
#
2025-11-11
Published