CyberICT

CVE-2025-59291

Microsoft · Published October 14, 2025

CVSS v3.1

HIGH
Patch availableGet patch

Description

Confidential Azure Container Instances Elevation of Privilege Vulnerability. External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally.

Affected Products

  • Azure Compute Gallery

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C