Impact
The vulnerability involves deserialization of untrusted data in Azure Monitor Agent. A user with authorized local access could exploit this flaw to elevate privileges on the affected machine. The weakness is identified as data deserialization vulnerability (CWE-502).
Affected Systems
Microsoft Azure Monitor Agent is affected. Specific version ranges have not been disclosed in the available data.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity impact, and although the EPSS score is not available, the vulnerability is not listed in the CISA KEV catalog. The attack requires local authorization and involves processing of untrusted data, suggesting that a privileged or temporarily authorized user could misuse the flaw to gain higher privileges. The risk remains significant until a vendor patch is applied.
OpenCVE Enrichment