Microsoft Azure Connected Machine Agent
cpe:2.3:a:microsoft:azure_connected_machine_agent:*:*:*:*:*:*:*
A vulnerability allowing external control of file names or paths in Azure Arc has been identified. This issue enables an authorized attacker to locally elevate privileges. The vulnerability arises in the Azure Connected Machine Agent, specifically in version 1.56.
Exploitation of this vulnerability allows an attacker to gain elevated privileges, enabling them to deploy virtual machine extensions on compromised servers.
Users can download the security update for the Azure Connected Machine Agent version 1.56 from the Microsoft Update Catalog.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.