CVE-2025-59292

8.2

Microsoft · Confidential Azure Container Instances

A path traversal vulnerability in Confidential Azure Container Instances allows an authorized attacker to achieve local privilege escalation via external control of file names or paths.

Executive summary

A high-severity path traversal vulnerability in Confidential Azure Container Instances allows an authenticated attacker to elevate privileges locally.

Vulnerability

The flaw is categorized as CWE-73, involving external control of file names or paths. An attacker with high privileges (as indicated by the CVSS vector PR:H) can manipulate file paths to elevate their local permissions within the affected environment.

Business impact

This vulnerability poses a significant risk to organizational security, as successful exploitation results in total impact to confidentiality, integrity, and availability. With a CVSS score of 8.2, this issue could allow an attacker to gain unauthorized control over container instances, leading to potential data exfiltration or the compromise of sensitive workloads hosted within the Azure environment.

Remediation

Immediate Action: Review the Microsoft Security Response Center (MSRC) update guide at the provided reference link and apply all relevant patches or configuration changes provided by Microsoft.

Proactive Monitoring: Monitor system logs for unusual file access patterns or attempts to access restricted directory paths within the container environment.

Compensating Controls: Implement strict identity and access management (IAM) policies to ensure that only the minimum necessary privileges are assigned to users, thereby limiting the potential damage of a privilege escalation event.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the high CVSS score and the potential for total system compromise, administrators should prioritize this vulnerability for remediation. Organizations using Confidential Azure Container Instances must consult the vendor advisory immediately to identify and apply the necessary security updates or configuration hardening steps to mitigate this escalation risk.

More Microsoft CVEs

Sources