Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-32168

Опубликовано: 14 апр. 2026
Источник: msrc
CVSS3: 7.8
EPSS Низкий

Описание

Azure Monitor Agent Elevation of Privilege Vulnerability

Improper input validation in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

FAQ

What privileges could an attacker gain with successful exploitation?

An attacker who successfully exploited the vulnerability could elevate their privileges to 'root' user.

How could an attacker exploit this vulnerability?

An attacker with the ability to run code as the syslog user on an affected Azure Linux Virtual Machine could modify specific configuration files used by the Azure Monitor agent. The agent processes these files with root‑level permissions and does not properly validate their contents, a malicious modification could cause the agent to execute unintended commands with elevated privileges. If exploited, the attacker could gain root access on the affected VM.

Обновления

ПродуктСтатьяОбновление
Azure Monitor Agent

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

EPSS

Процентиль: 22%
0.00307
Низкий

7.8 High

CVSS3

Связанные уязвимости

CVSS3: 7.8
nvd
4 месяца назад

Improper input validation in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
github
4 месяца назад

Improper input validation in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.

CVSS3: 7.8
fstec
4 месяца назад

Уязвимость инструмента сбора данных с виртуальных машин (VM) и физических серверов Azure Monitor Agent, связанная с недостаточной проверкой входных данных, позволяющая нарушителю повысить свои привилегии

EPSS

Процентиль: 22%
0.00307
Низкий

7.8 High

CVSS3