CVE-2025-62550

8.8

Microsoft · Azure Monitor Agent

An out-of-bounds write vulnerability in the Microsoft Azure Monitor Agent allows an authorized attacker to execute arbitrary code over a network.

Executive summary

A critical out-of-bounds write vulnerability in the Microsoft Azure Monitor Agent enables authorized attackers to achieve remote code execution.

Vulnerability

This flaw stems from an out-of-bounds write and incorrect buffer size calculation, which can be triggered by an authorized (authenticated) attacker over a network to execute code.

Business impact

Successful exploitation of this vulnerability permits unauthorized code execution with the privileges of the agent, potentially leading to full system compromise. Given the CVSS score of 8.8, this represents a high-severity risk that could facilitate lateral movement within the environment or data exfiltration. Organizations relying on Azure Monitor for infrastructure visibility are at risk of significant operational disruption if the agent is compromised.

Remediation

Immediate Action: Update the Microsoft Azure Monitor Agent to version 1.35.9 or later immediately to resolve the vulnerable code path.

Proactive Monitoring: Review system and agent logs for unexpected process execution or abnormal spikes in memory utilization that may indicate exploitation attempts.

Compensating Controls: Restrict network access to the management interfaces of the affected agents to authorized administrative subnets only to limit the attack surface.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Due to the severity of this remote code execution vulnerability, IT administrators must prioritize the deployment of the vendor-supplied patch. Organizations should verify their current agent versions across all Azure resources and apply the update to version 1.35.9 to mitigate the risk of unauthorized system access.

More Microsoft CVEs

Sources