Microsoft Azure Arc Privilege Escalation Vulnerability via Command Injection

Vulnerability

A command injection vulnerability in Azure Arc allows authorized attackers to locally elevate privileges. This issue arises from improper handling of special elements in commands, enabling exploitation by manipulating command execution. The vulnerability affects Azure Arc installations via Group Policy, specifically those with the GPO '[MSFT] Azure Arc Servers Onboarding' applied.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing attackers to gain SYSTEM privileges.

Remediation

To address this vulnerability, unassign and delete the existing Group Policy Object from the Group Policy Management Console. Then, download the updated scripts from the 'Fixed agent proxy parameter' release version 1.0.10 in the Azure Arc Enabled Servers Group Policy GitHub repository. Afterward, run the DeployGPO script with the same parameters as before and assign the new Group Policy Object to the appropriate groups, domains, or units.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
3.3
remediation
8.3
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.