CVE-2025-59285High· 7.0▾ TwilightDeserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 38.5 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.8%
Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
azure_monitor_agent < 1.36.3Upgrade past the affected range:
azure_monitor_agent 1.36.3Connected by shared product, vendor, weakness, or advisory.
CVE-2020-0618High· 8.8A remote code execution vulnerability exists in Microsoft SQL Server Reporting Services when it incorrectly handles page requests, aka 'Microsoft SQL Server Reporting Services Remote Code Execution Vulnerability'.
CVE-2021-26857High· 7.8Microsoft Exchange Server Remote Code Execution Vulnerability
CVE-2024-35249High· 8.8Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability
CVE-2025-59494High· 7.8Improper access control in Azure Monitor Agent allows an authorized attacker to elevate privileges locally.
CVE-2021-34520High· 8.1Microsoft SharePoint Server Remote Code Execution Vulnerability
CVE-2024-35254High· 7.1Azure Monitor Agent Elevation of Privilege Vulnerability