Executive brief
A security vulnerability exists in the Microsoft Azure Monitor Agent, a tool used to collect telemetry data from virtual machines and servers. An attacker who already has basic access to a system could exploit this flaw to gain higher-level administrative permissions. This could allow them to bypass security controls or interfere with system monitoring and integrity.
Technical details
An untrusted search path vulnerability (CWE-426) exists in the Microsoft Azure Monitor Agent. The flaw occurs when the application attempts to load a resource or library without specifying a fully qualified path, potentially allowing a local attacker to place a malicious file in a directory searched by the application. To exploit this, an attacker must have local access with low-level privileges. Successful exploitation allows the attacker to execute code with elevated privileges, potentially impacting the integrity of the host system. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Azure Monitor Agent
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory