CVE-2025-59291

8.2

Microsoft · Confidential Azure Container Instances

A path traversal vulnerability in Confidential Azure Container Instances allows a local authorized attacker to elevate privileges.

Executive summary

A privilege escalation vulnerability in Confidential Azure Container Instances poses a significant security risk to cloud infrastructure environments.

Vulnerability

This flaw involves the external control of a file name or path (CWE-73), which allows an attacker with high privileges to manipulate system files and achieve local privilege escalation. The vulnerability requires the attacker to be already authenticated with high-level access to the environment.

Business impact

The ability for a privileged user to escalate their permissions locally can lead to complete host compromise, unauthorized data access, and the potential for lateral movement within the cloud environment. With a CVSS score of 8.2, this vulnerability is classified as High, reflecting the severe impact on system confidentiality, integrity, and availability should an attacker successfully weaponize this flaw.

Remediation

Immediate Action: Review the official Microsoft Security Response Center update guide for the latest patches and configuration changes.

Proactive Monitoring: Monitor system access logs for anomalous file path requests or unauthorized attempts to access sensitive system directories.

Compensating Controls: Implement strict identity and access management policies to limit high-privilege accounts and ensure the principle of least privilege is enforced.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Security teams should treat this vulnerability with high priority, given its potential for privilege escalation within containerized environments. Administrators must consult the provided Microsoft MSRC reference immediately to identify specific affected instances and apply necessary updates or configuration hardening steps to mitigate the risk of local exploitation.

More Microsoft CVEs

Sources