CVE-2025-47988

Improper control of generation of code ('code injection') in Azure Monitor Agent allows an unauthorized attacker to execute code over an adjacent network.
Configurations

Configuration 1 (hide)

cpe:2.3:a:microsoft:azure_monitor_agent:*:*:*:*:*:*:*:*

History

23 Jul 2025, 18:48

Type Values Removed Values Added
CPE cpe:2.3:a:microsoft:azure_monitor_agent:*:*:*:*:*:*:*:*
References () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47988 - () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47988 - Vendor Advisory
First Time Microsoft azure Monitor Agent
Microsoft

10 Jul 2025, 13:19

Type Values Removed Values Added
Summary
  • (es) El control inadecuado de la generación de código ('inyección de código') en el Agente de Azure Monitor permite que un atacante no autorizado ejecute código en una red adyacente.

08 Jul 2025, 17:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-08 17:15

Updated : 2025-07-23 18:48


NVD link : CVE-2025-47988

Mitre link : CVE-2025-47988

CVE.ORG link : CVE-2025-47988


JSON object : View

Products Affected

microsoft

  • azure_monitor_agent
CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')