Microsoft Azure Monitor Agent vulnerabilities
12 known vulnerabilities affecting microsoft/azure_monitor_agent.
Total CVEs
12
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH11MEDIUM1
Vulnerabilities
Page 1 of 1
CVE-2025-62550P2HIGHCVSS 8.8fixed in 1.35.92025-12-09
CVE-2025-62550 [HIGH] CWE-131 CVE-2025-62550: Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a netw
Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network.
nvd
CVE-2026-32192P3HIGHCVSS 7.8fixed in 1.41.02026-04-14
CVE-2026-32192 [HIGH] CWE-502 CVE-2026-32192: Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate pr
Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59494P3HIGHCVSS 7.8fixed in 1.38.12025-10-14
CVE-2025-59494 [HIGH] CWE-284 CVE-2025-59494: Improper access control in Azure Monitor Agent allows an authorized attacker to elevate privileges l
Improper access control in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32168P3HIGHCVSS 7.8fixed in 1.35.92026-04-14
CVE-2026-32168 [HIGH] CWE-20 CVE-2026-32168: Improper input validation in Azure Monitor Agent allows an authorized attacker to elevate privileges
Improper input validation in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-47988P3HIGHCVSS 7.5fixed in 1.35.12025-07-08
CVE-2025-47988 [HIGH] CWE-94 CVE-2025-47988: Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthori
Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthorized attacker to execute code over an adjacent network.
nvd
CVE-2025-59504P3HIGHCVSS 7.3fixed in 1.37.12025-11-11
CVE-2025-59504 [HIGH] CWE-122 CVE-2025-59504: Heap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code lo
Heap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code locally.
nvd
CVE-2024-29989P3HIGHCVSS 8.4fixed in 1.24.02024-04-09
CVE-2024-29989 [HIGH] CWE-59 CVE-2024-29989: Azure Monitor Agent Elevation of Privilege Vulnerability
Azure Monitor Agent Elevation of Privilege Vulnerability
nvd
CVE-2024-30060P3HIGHCVSS 7.8fixed in 1.26.02024-05-16
CVE-2024-30060 [HIGH] CWE-59 CVE-2024-30060: Azure Monitor Agent Elevation of Privilege Vulnerability
Azure Monitor Agent Elevation of Privilege Vulnerability
nvd
CVE-2025-59285P3HIGHCVSS 7.0fixed in 1.36.32025-10-14
CVE-2025-59285 [HIGH] CWE-502 CVE-2025-59285: Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate pr
Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-35254P4HIGHCVSS 7.1fixed in 1.26.02024-06-11
CVE-2024-35254 [HIGH] CWE-59 CVE-2024-35254: Azure Monitor Agent Elevation of Privilege Vulnerability
Azure Monitor Agent Elevation of Privilege Vulnerability
nvd
CVE-2026-42830P4MEDIUMCVSS 6.5fixed in 1.42.02026-05-12
CVE-2026-42830 [MEDIUM] CWE-426 CVE-2026-42830: Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges loc
Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-38097P4HIGHCVSS 7.1fixed in 1.30.02024-10-08
CVE-2024-38097 [HIGH] CWE-59 CVE-2024-38097: Azure Monitor Agent Elevation of Privilege Vulnerability
Azure Monitor Agent Elevation of Privilege Vulnerability
nvd