Microsoft Azure Connected Machine Agent
cpe:2.3:a:microsoft:azure_connected_machine_agent:*:*:*:*:*:*:*
A vulnerability in the Azure Windows Virtual Machine Agent has been identified, allowing an authorized attacker to bypass authentication and elevate privileges locally. This issue arises from an authentication bypass using an alternate path or channel.
Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing an attacker to gain SYSTEM privileges.
Users can download the security update for this vulnerability via the Microsoft Update Catalog. Instructions for installing a specific version of the Azure Connected Machine Agent on Linux are also available on the Microsoft Learn website.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.