CVE-2025-59292

HIGH

Confidential Azure Container Instances - Privilege Escalation

Title source: llm

Description

External control of file name or path in Confidential Azure Container Instances allows an authorized attacker to elevate privileges locally.

Scores

CVSS v3 8.2
EPSS 0.0021
EPSS Percentile 43.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

Classification

CWE
CWE-73
Status published

Affected Products (1)

microsoft/azure_compute_gallery

Timeline

Published Oct 14, 2025
Tracked Since Feb 18, 2026