CVE-2025-62550
8.8Microsoft · Azure Monitor Agent
An out-of-bounds write vulnerability in the Microsoft Azure Monitor Agent allows an authorized attacker to execute arbitrary code over a network.
Executive summary
A critical out-of-bounds write vulnerability in the Microsoft Azure Monitor Agent enables authorized attackers to achieve remote code execution.
Vulnerability
This flaw stems from an out-of-bounds write and incorrect buffer size calculation, which can be triggered by an authorized (authenticated) attacker over a network to execute code.
Business impact
Successful exploitation of this vulnerability permits unauthorized code execution with the privileges of the agent, potentially leading to full system compromise. Given the CVSS score of 8.8, this represents a high-severity risk that could facilitate lateral movement within the environment or data exfiltration. Organizations relying on Azure Monitor for infrastructure visibility are at risk of significant operational disruption if the agent is compromised.
Remediation
Immediate Action: Update the Microsoft Azure Monitor Agent to version 1.35.9 or later immediately to resolve the vulnerable code path.
Proactive Monitoring: Review system and agent logs for unexpected process execution or abnormal spikes in memory utilization that may indicate exploitation attempts.
Compensating Controls: Restrict network access to the management interfaces of the affected agents to authorized administrative subnets only to limit the attack surface.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Due to the severity of this remote code execution vulnerability, IT administrators must prioritize the deployment of the vendor-supplied patch. Organizations should verify their current agent versions across all Azure resources and apply the update to version 1.35.9 to mitigate the risk of unauthorized system access.
More Microsoft CVEs
Sources
- Azure Monitor Agent Remote Code Execution Vulnerability Vendor advisory