#VU105535 Command Injection in Azure CLI - CVE-2025-24049
Published: March 11, 2025
Azure CLI
Microsoft
Description
The vulnerability allows a local attacker to execute arbitrary commands on the target system.
The vulnerability exists due to improper input validation in Azure Command Line Integration (CLI). A local attacker can pass specially crafted data to the application and execute arbitrary commands on the target system with elevated privileges.