cbcvebase.

Microsoft Azure Monitor Agent vulnerabilities

12 known vulnerabilities affecting microsoft/azure_monitor_agent.

Total CVEs
12
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
HIGH11MEDIUM1

Vulnerabilities

Page 1 of 1
CVE-2025-62550P2HIGHCVSS 8.8fixed in 1.35.92025-12-09
CVE-2025-62550 [HIGH] CWE-131 CVE-2025-62550: Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a netw Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network.
nvd
CVE-2026-32192P3HIGHCVSS 7.8fixed in 1.41.02026-04-14
CVE-2026-32192 [HIGH] CWE-502 CVE-2026-32192: Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate pr Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-59494P3HIGHCVSS 7.8fixed in 1.38.12025-10-14
CVE-2025-59494 [HIGH] CWE-284 CVE-2025-59494: Improper access control in Azure Monitor Agent allows an authorized attacker to elevate privileges l Improper access control in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
nvd
CVE-2026-32168P3HIGHCVSS 7.8fixed in 1.35.92026-04-14
CVE-2026-32168 [HIGH] CWE-20 CVE-2026-32168: Improper input validation in Azure Monitor Agent allows an authorized attacker to elevate privileges Improper input validation in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
nvd
CVE-2025-47988P3HIGHCVSS 7.5fixed in 1.35.12025-07-08
CVE-2025-47988 [HIGH] CWE-94 CVE-2025-47988: Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthori Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthorized attacker to execute code over an adjacent network.
nvd
CVE-2025-59504P3HIGHCVSS 7.3fixed in 1.37.12025-11-11
CVE-2025-59504 [HIGH] CWE-122 CVE-2025-59504: Heap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code lo Heap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code locally.
nvd
CVE-2024-29989P3HIGHCVSS 8.4fixed in 1.24.02024-04-09
CVE-2024-29989 [HIGH] CWE-59 CVE-2024-29989: Azure Monitor Agent Elevation of Privilege Vulnerability Azure Monitor Agent Elevation of Privilege Vulnerability
nvd
CVE-2024-30060P3HIGHCVSS 7.8fixed in 1.26.02024-05-16
CVE-2024-30060 [HIGH] CWE-59 CVE-2024-30060: Azure Monitor Agent Elevation of Privilege Vulnerability Azure Monitor Agent Elevation of Privilege Vulnerability
nvd
CVE-2025-59285P3HIGHCVSS 7.0fixed in 1.36.32025-10-14
CVE-2025-59285 [HIGH] CWE-502 CVE-2025-59285: Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate pr Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-35254P4HIGHCVSS 7.1fixed in 1.26.02024-06-11
CVE-2024-35254 [HIGH] CWE-59 CVE-2024-35254: Azure Monitor Agent Elevation of Privilege Vulnerability Azure Monitor Agent Elevation of Privilege Vulnerability
nvd
CVE-2026-42830P4MEDIUMCVSS 6.5fixed in 1.42.02026-05-12
CVE-2026-42830 [MEDIUM] CWE-426 CVE-2026-42830: Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges loc Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
nvd
CVE-2024-38097P4HIGHCVSS 7.1fixed in 1.30.02024-10-08
CVE-2024-38097 [HIGH] CWE-59 CVE-2024-38097: Azure Monitor Agent Elevation of Privilege Vulnerability Azure Monitor Agent Elevation of Privilege Vulnerability
nvd
Microsoft Azure Monitor Agent vulnerabilities | cvebase