Microsoft · Azure Monitor Agent · CVE-2024-38097
**Name of the Vulnerable Software and Affected Versions**
Azure Monitor Agent (affected versions not specified)
**Description**
The issue is related to an elevation of privilege vulnerability in the Azure Monitor Agent, which is used for data collection from virtual machines (VM) and physical servers. The vulnerability is caused by an incorrect reference definition before accessing a file. Exploitation of this issue may allow an attacker to elevate their privileges.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.