Microsoft Azure File Sync Improper Access Control Vulnerability Allowing Privilege Escalation

Vulnerability

A vulnerability in Azure File Sync has been identified, allowing an authorized attacker to improperly elevate privileges locally. This issue arises from inadequate access control within the application.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing an attacker to gain SYSTEM privileges.

Remediation

Users can apply the security update available in Azure File Sync versions 18.3.0.0, 19.2.0.0, 20.1.0.0, and 21.1.0.0. Instructions for downloading this update are available on the Microsoft Support website.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
3.3
remediation
7.7
relevance
0.4
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.