Microsoft Azure Connected Machine Agent
cpe:2.3:a:microsoft:azure_connected_machine_agent:*:*:*:*:*:*:*
A vulnerability allowing improper access control in the Azure Connected Machine Agent on Arc Enabled Servers has been identified. This flaw enables an authorized attacker to locally elevate privileges, potentially gaining SYSTEM rights.
Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing an attacker to gain SYSTEM privileges.
Users can download the security update for this vulnerability from the Microsoft Update Catalog. Instructions for installing a specific version of the Azure Connected Machine Agent are also available on the Microsoft Learn website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.