CVE-2025-24049: Microsoft Azure Command-Line Interface
High severity, CVSS 8.4. EPSS: 0.4% chance of exploitation in the next 30 days.
Improper neutralization of special elements used in a command ('command injection') in Azure Command Line Integration (CLI) allows an unauthorized attacker to elevate privileges locally.
Affected products
- Microsoft Azure Command-Line Interface: before 2.69.0 (fixed in 2.69.0)
Published 2025-03-11. Last modified 2026-06-17.