#VU117169 Deserialization of Untrusted Data in Azure Monitor Agent - CVE-2025-59285
Published: October 15, 2025
Azure Monitor Agent
Microsoft
Description
The vulnerability allows a local user to execute arbitrary code on the target system.
The vulnerability exists due to insecure input validation when processing serialized data in Azure Monitor Agent. A local user can pass specially crafted data to the application and execute arbitrary code on the target system with elevated privileges.