Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network.
What kind of security feature could be bypassed by successfully exploiting this vulnerability? Successfully exploiting this vulnerability could bypass extension allowlist–based protections that are intended to limit which Azure Arc or Azure VM extensions can perform actions on a machine. In certain hardened configurations, this could allow a monitoring-only extension to run commands with elevated privileges in ways that were not intended by the security configuration.
<a href="https://twitter.com/ronmasas">Ron Masas</a>