PT-2025-42151 · Microsoft · Azure Container Instance

Published

2025-10-14

·

Updated

2025-10-17

·

CVE-2025-59291

CVSS v3.1

8.2

High

VectorAV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Azure Container Instances (ACI) (affected versions not specified)
Description An issue exists in Azure Container Instances where external control of a file name or path can allow an authorized attacker to elevate privileges locally. The flaw involves manipulating file names or paths during container deployment or management, potentially leading to unauthorized access or control over the container environment.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Weakness Enumeration

Related Identifiers

BDU:2025-12997
CVE-2025-59291

Affected Products

Azure Container Instance