Microsoft Azure Arc Elevation of Privilege Vulnerability

Vulnerability

A vulnerability allowing external control of file names or paths in Azure Arc has been identified. This issue enables an authorized attacker to locally elevate privileges. The vulnerability arises in the Azure Connected Machine Agent, specifically in version 1.56.

Impact

Exploitation of this vulnerability allows an attacker to gain elevated privileges, enabling them to deploy virtual machine extensions on compromised servers.

Remediation

Users can download the security update for the Azure Connected Machine Agent version 1.56 from the Microsoft Update Catalog.

Added: Sep 9, 2025, 7:22 PM
Updated: Sep 9, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
4.2
impact
5.0
exploitability
3.3
remediation
7.7
relevance
0.5
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.