CVE-2025-24049

Improper neutralization of special elements used in a command ('command injection') in Azure Command Line Integration (CLI) allows an unauthorized attacker to elevate privileges locally.
Configurations

Configuration 1 (hide)

cpe:2.3:a:microsoft:azure_command-line_interface:*:*:*:*:*:*:*:*

History

02 Jul 2025, 16:09

Type Values Removed Values Added
References () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24049 - () https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-24049 - Vendor Advisory
First Time Microsoft azure Command-line Interface
Microsoft
CPE cpe:2.3:a:microsoft:azure_command-line_interface:*:*:*:*:*:*:*:*
Summary
  • (es) La neutralización incorrecta de elementos especiales utilizados en un comando ("inyección de comando") en Azure Command Line Integration (CLI) permite que un atacante no autorizado eleve privilegios localmente.

11 Mar 2025, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2025-03-11 17:16

Updated : 2025-07-02 16:09


NVD link : CVE-2025-24049

Mitre link : CVE-2025-24049

CVE.ORG link : CVE-2025-24049


JSON object : View

Products Affected

microsoft

  • azure_command-line_interface
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')