Microsoft Azure Local Privilege Escalation Vulnerability

Vulnerability

A heap-based buffer overflow vulnerability has been identified in Azure Local, allowing an authorized attacker to elevate privileges locally. This vulnerability affects several versions of Windows Server 2025 and Windows Server 2022, 23H2 Edition (Server Core installation).

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing an attacker to gain SYSTEM privileges.

Remediation

Users can download the security update for this vulnerability via the Microsoft Update Catalog. Security Update KB5066835 is available for Windows Server 2025 and Windows Server 2025 (Server Core installation). Security Update KB5066780 can be downloaded for Windows Server 2022, 23H2 Edition (Server Core installation).

Added: Oct 14, 2025, 7:40 PM
Updated: Oct 14, 2025, 7:40 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
3.3
remediation
0.0
relevance
0.7
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.