Microsoft Azure Arc Improper Authentication Vulnerability Allowing Privilege Elevation
Vulnerability
A vulnerability has been identified in the Azure Arc Hybrid Worker Extension for Arc-enabled Windows VMs, related to improper authentication. This flaw allows an authorized attacker to locally elevate privileges. The vulnerability affects versions of the Azure Automation Hybrid Worker Windows Extension prior to the security update released on March 10, 2026.
Impact
Exploitation of this vulnerability could lead to unauthorized privilege escalation.
Remediation
Users can download the security update for the Azure Automation Hybrid Worker Windows Extension from the Microsoft Learn website. Instructions for installation are also available there.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
