CVE-2026-32192 is a deserialization vulnerability affecting Azure Monitor Agent that permits authorized local users to execute arbitrary code with elevated privileges on affected systems. The vulnerability stems from improper handling of untrusted data during the deserialization process, creating a privilege escalation vector for authenticated attackers with local access. With a CVSS score of 7.8 (HIGH), this vulnerability carries significant risk due to its high impact across confidentiality, integrity, and availability, combined with low attack complexity and no user interaction requirement. The vulnerability currently shows minimal active exploitation, as it does not appear on Microsoft's Known Exploited Vulnerabilities catalog and remains on the inactive hot list, suggesting limited real-world abuse to date. Organizations running Azure Monitor Agent should prioritize patching efforts given the high severity rating and the presence of a straightforward attack vector requiring only local access and standard user privileges.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.41.0CPE matchmatch criteria | cpe:2.3:a:microsoft:azure_monitor_agent:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.