Description
Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
Problem types
CWE-502: Deserialization of Untrusted Data
Product status
References
msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59285 (Azure Monitor Agent Elevation of Privilege Vulnerability)