Microsoft Azure Connected Machine Agent
cpe:2.3:a:microsoft:azure_connected_machine_agent:*:*:*:*:*:*:*
A stack-based buffer overflow vulnerability has been identified in the Azure Connected Machine Agent. This vulnerability allows an authorized attacker to locally elevate privileges. The issue arises from the agent's handling of data, which can be exploited to overwrite memory and execute arbitrary code with elevated rights.
Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing an attacker to gain SYSTEM privileges.
Users can download the latest version of the Azure Connected Machine Agent for Windows via the Windows Update service or directly from the Microsoft Update Catalog. For Linux, instructions are available on the Microsoft Learn website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.