CyberICT

CVE-2025-59292

Microsoft · Published October 14, 2025

CVSS v3.1

HIGH
Patch availableGet patch

Description

Azure Compute Gallery Elevation of Privilege Vulnerability. External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally.

Affected Products

  • Azure Compute Gallery

CVSS Vector

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C