Microsoft Azure Arc Improper Authentication Vulnerability Allowing Privilege Elevation

Vulnerability

A vulnerability has been identified in the Azure Arc Hybrid Worker Extension for Arc-enabled Windows VMs, related to improper authentication. This flaw allows an authorized attacker to locally elevate privileges. The vulnerability affects versions of the Azure Automation Hybrid Worker Windows Extension prior to the security update released on March 10, 2026.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation.

Remediation

Users can download the security update for the Azure Automation Hybrid Worker Windows Extension from the Microsoft Learn website. Instructions for installation are also available there.

Added: Mar 10, 2026, 7:06 PM
Updated: Mar 10, 2026, 7:06 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
2.9
remediation
0.0
relevance
3.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.