Microsoft Azure Monitor Agent
cpe:2.3:a:microsoft:azure_monitor_agent:*:*:*:*:*:*:*
A vulnerability allowing improper access control in Azure Monitor Agent has been identified, which could enable an authorized attacker to locally elevate privileges. This issue affects all versions of Azure Monitor Agent prior to the security update released on October 14, 2025.
Exploitation of this vulnerability allows a regular user on an Arc-enabled virtual machine to read any file on the system with NT SYSTEM privileges.
Users can download the security update for Azure Monitor Agent from the Microsoft Learn website. For more information on managing the Azure Monitor Agent, refer to the release notes available on the same site.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.