cbcvebase.
CVE-2025-62550
published 2025-12-09

CVE-2025-62550: Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network.

PriorityP260high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
0.69%
48.3th percentile
Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network.

Affected

3 ranges
VendorProductVersion rangeFixed in
microsoftazure_monitor>= 1.0.0 < 1.35.91.35.9
microsoftazure_monitor_agent< 1.35.91.35.9
msrcazure_monitor_agent

Detection & IOCsextracted from sources · hover to see the quote

  • Look for exploitation attempts targeting Azure Monitor Agent on Azure Linux Virtual Machines via local network access — attacker exploits a heap overflow to escalate privileges to the syslog user and execute arbitrary commands.
  • Any authenticated (low-privilege) user can trigger this vulnerability over the network — monitor for unexpected privilege escalation to the syslog user on Azure Linux VMs running Azure Monitor Agent.
  • The vulnerability is an out-of-bounds write (heap overflow) in Azure Monitor Agent — monitor for anomalous memory corruption signals or crashes in the Azure Monitor Agent process on Linux VMs.
  • ·No public exploit exists as of the advisory date; exploitation is assessed as 'Less Likely' by Microsoft. Fixes were added December 11–12, 2025 for both Linux and Windows platforms — patch Azure Monitor Agent to the fixed version.
  • ·The attack vector requires local network access to the Azure Linux VM running Azure Monitor Agent — network segmentation limiting access to the agent's listening port reduces exposure.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.