Microsoft Azure Local Improper Certificate Validation Leading to Remote Code Execution Vulnerability

Vulnerability

A remote code execution vulnerability has been identified in Azure Local due to improper certificate validation. This issue allows an unauthorized attacker to execute code over the network. Exploitation involves intercepting unsecure communications between the configurator app and target machines, modifying responses to inject commands that execute arbitrary code with administrative privileges. The vulnerability affects Azure Local versions through 2510.0.3002.

Impact

Exploitation of this vulnerability allows for remote code execution on the affected system, with the executed code running with administrative privileges.

Remediation

Users are advised to download the security update for Azure Local available through the Microsoft Update Catalog. Instructions for applying the update can be found in the Azure Local release notes.

Added: Feb 10, 2026, 7:16 PM
Updated: Feb 11, 2026, 2:15 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
6.0
remediation
0.0
relevance
3.0
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.