Microsoft Azure Monitor Agent Code Injection Vulnerability Allowing Unauthorized Code Execution

Vulnerability

A code injection vulnerability has been identified in the Azure Monitor Agent. This issue allows an unauthorized attacker to execute code on a system over an adjacent network. The vulnerability arises from improper control over the generation of code, enabling potential exploitation.

Impact

Exploitation of this vulnerability could lead to unauthorized code execution on the affected system.

Added: Jul 8, 2025, 10:14 PM
Updated: Jul 8, 2025, 10:14 PM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
7.5
exploitability
4.7
remediation
0.0
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.