Microsoft
Microsoft Azure Monitor Agent: vulnerabilidades y CVE
Microsoft Azure Monitor Agent tiene 14 vulnerabilidades publicadas, 9 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE14
Últimos 12 meses9
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-47299 | Alta (7.2) | 1.0% | — | 11 ago 2026 | Improper neutralization of special elements used in a command ('command injection') in Azure Monitor Agent allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-42830 | Media (6.5) | 0.64% | — | 12 may 2026 | Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. |
| CVE-2026-32204 | Alta (7.8) | 0.36% | — | 12 may 2026 | External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. |
| CVE-2026-32192 | Alta (7.8) | 2.5% | — | 14 abr 2026 | Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. |
| CVE-2026-32168 | Alta (7.8) | 0.33% | — | 14 abr 2026 | Improper input validation in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. |
| CVE-2025-62550 | Alta (8.8) | 0.74% | — | 9 dic 2025 | Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network. |
| CVE-2025-59504 | Alta (7.3) | 0.33% | — | 11 nov 2025 | Heap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code locally. |
| CVE-2025-59494 | Alta (7.8) | 0.64% | — | 14 oct 2025 | Improper access control in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. |
| CVE-2025-59285 | Alta (7) | 0.78% | — | 14 oct 2025 | Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. |
| CVE-2025-47988 | Alta (7.5) | 0.96% | — | 8 jul 2025 | Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthorized attacker to execute code over an adjacent network. |
| CVE-2024-38097 | Alta (7.1) | 0.65% | — | 8 oct 2024 | Azure Monitor Agent Elevation of Privilege Vulnerability |
| CVE-2024-35254 | Alta (7.1) | 0.83% | — | 11 jun 2024 | Azure Monitor Agent Elevation of Privilege Vulnerability |
| CVE-2024-30060 | Alta (7.8) | 0.49% | — | 16 may 2024 | Azure Monitor Agent Elevation of Privilege Vulnerability |
| CVE-2024-29989 | Alta (8.4) | 0.75% | — | 9 abr 2024 | Azure Monitor Agent Elevation of Privilege Vulnerability |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.