Impact
The vulnerability arises from improper neutralization of special elements used in a command, which Microsoft classifies as a command injection flaw (CWE‑77). An attacker who has authorized access to the Azure Monitor Agent Linux Extension can construct input that is passed unchanged to the underlying operating‑system shell, enabling the execution of arbitrary commands. The primary consequence is elevation of privileges over the network, allowing the attacker to gain higher authority on the host or potentially on other systems accessed by the agent.
Affected Systems
The flaw affects Microsoft’s Azure Monitor Agent Linux Extension. No specific version applicability was disclosed, so all operational instances of this agent are potentially vulnerable until the Microsoft update is applied.
Risk and Exploitability
The CVSS score of 7.2 indicates a high‑severity condition. The EPSS score of less than 1 % suggests that exploitation is unlikely at present, and the vulnerability has not been reported as part of the CISA KEV catalog. The attack requires an attacker to possess legitimate credentials or some authorized capability to interact with the agent; from that position the actor can craft malicious input and cause the agent to run commands with elevated privileges. Consequently, internal adversaries with valid access or compromised credentials pose the highest risk.
OpenCVE Enrichment