Microsoft Azure Monitor Agent
cpe:2.3:a:microsoft:azure_monitor_agent:*:*:*:*:*:*:*
A vulnerability in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. This issue arises from external control of file names or paths, as the agent does not properly validate incoming configuration messages. Exploitation could enable an attacker to write files on the system, potentially leading to the execution of unauthorized code.
Exploitation of this vulnerability could allow an attacker to gain 'root' privileges on the affected system.
Users are advised to download the security update for Azure Monitor Agent. Instructions can be found in the Azure Monitor Agent release notes.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.