Azure CLI
by Microsoft
CVEs (4)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-36052 | Hig | 0.58 | 8.6 | 0.21 | Nov 14, 2023 | Azure CLI REST Command Information Disclosure Vulnerability | ||
| CVE-2024-43591 | Hig | 0.57 | 8.7 | 0.02 | Oct 8, 2024 | Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability | ||
| CVE-2025-24049 | Hig | 0.55 | 8.4 | 0.00 | Mar 11, 2025 | Improper neutralization of special elements used in a command ('command injection') in Azure Command Line Integration (CLI) allows an unauthorized attacker to elevate privileges locally. | ||
| CVE-2026-83948 | Hig | 0.52 | 8.0 | 0.00 | Sep 8, 2026 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Azure CLI allows an authorized attacker to execute code over a network. |
- risk 0.58cvss 8.6epss 0.21
Azure CLI REST Command Information Disclosure Vulnerability
- risk 0.57cvss 8.7epss 0.02
Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability
- risk 0.55cvss 8.4epss 0.00
Improper neutralization of special elements used in a command ('command injection') in Azure Command Line Integration (CLI) allows an unauthorized attacker to elevate privileges locally.
- risk 0.52cvss 8.0epss 0.00
Improper neutralization of special elements used in a command ('command injection') in Microsoft Azure CLI allows an authorized attacker to execute code over a network.