CVE-2025-59494: Azure Monitor Agent Elevation of Privilege Vulnerability

Overview

Severity
High (CVSS 7.8)
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Category
Elevation of Privilege
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2025-Oct
Released
2025-10-14
EPSS Score
0.05% (percentile: 17.2%)

Description

Improper access control in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

FAQ

What privileges could be gained by an attacker who successfully exploited the vulnerability? A successful exploitation of this vulnerability allows a regular user on an Arc-enabled VM to read any file on the system with NT SYSTEM privileges.

Affected Products (1)

Azure

  • Azure Monitor Agent

Security Updates (1)

Acknowledgments

Michal Kamensky with Microsoft

Revision History

  • 2025-10-14: Information published.