Azure Monitor Agent
Vendor:
First CVE: Apr 9, 2024 · Active for 2 years
13
Total CVEs
More Total CVEs than 91% of tracked products
4.3
Avg CVEs / Year
Higher CVE frequency than 86% of tracked products
7.6
Avg CVSS
Higher Avg CVSS than 60% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Azure Monitor Agent over time
Volume of CVEsAvg CVSS Base Score
First CVE
Apr 9, 2024
2 years ago
Most Recent CVE
May 12, 2026
73 days ago
CVE Severity & Scoring
Azure Monitor Agent13 CVEs
92%
All CVEs352,294 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local11 (84.6%)
Network1 (7.7%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network1 (7.7%)
Attack Complexity
Low11 (84.6%)
High2 (15.4%)
Unknown0 (0.0%)
User Interaction
None13 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low11 (84.6%)
High0 (0.0%)
None2 (15.4%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (13 CVEs).
13 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-32204HIGH External control of file name or path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. | May 12, 2026 | 7.8 | 29 | NO | NO |
CVE-2025-62550HIGH Out-of-bounds write in Azure Monitor Agent allows an authorized attacker to execute code over a network. | Dec 9, 2025 | 8.8 | 28 | NO | NO |
CVE-2026-42830MEDIUM Untrusted search path in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. | May 12, 2026 | 6.5 | 27 | NO | NO |
CVE-2026-32192HIGH Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. | Apr 14, 2026 | 7.8 | 27 | NO | NO |
CVE-2026-32168HIGH Improper input validation in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. | Apr 14, 2026 | 7.8 | 26 | NO | NO |
CVE-2025-59504HIGH Heap-based buffer overflow in Azure Monitor Agent allows an unauthorized attacker to execute code locally. | Nov 11, 2025 | 7.3 | 25 | NO | NO |
CVE-2025-59494HIGH Improper access control in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. | Oct 14, 2025 | 7.8 | 24 | NO | NO |
CVE-2025-59285HIGH Deserialization of untrusted data in Azure Monitor Agent allows an authorized attacker to elevate privileges locally. | Oct 14, 2025 | 7.0 | 23 | NO | NO |
CVE-2024-30060HIGH Azure Monitor Agent Elevation of Privilege Vulnerability | May 16, 2024 | 7.8 | 23 | NO | NO |
CVE-2024-29989HIGH Azure Monitor Agent Elevation of Privilege Vulnerability | Apr 9, 2024 | 8.4 | 23 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (13 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (13 CVEs).
Media Mentions
Signals from CVEs in this product scope (13 CVEs).
Top CNAs Publishing CVEs For Azure Monitor Agent
Top CWEs
Versions
No cataloged versions.