CVE-2025-59291
Microsoft · Published October 14, 2025
8.2
CVSS v3.1
HIGHPatch availableGet patch
Description
Confidential Azure Container Instances Elevation of Privilege Vulnerability. External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally.
Affected Products
- Azure Compute Gallery
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C