CVE-2025-21199: Azure Agent Installer for Backup and Site Recovery Elevation of Privilege Vulnerability

Overview

Severity
Medium (CVSS 6.7)
CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Category
Elevation of Privilege
Exploit Status
Not Exploited
Exploitation Likelihood
Less Likely
Patch Tuesday
2025-Mar
Released
2025-03-11
Last Updated
2025-04-25
EPSS Score
0.21% (percentile: 43.4%)

Description

Improper privilege management in Azure Agent Installer allows an authorized attacker to elevate privileges locally.

FAQ

According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do? Successful exploitation of this vulnerability requires an administrator to install the bootstrapping agent on the target device where an attacker has planted specially crafted malicious files. According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires an attacker to have access to the location where the target file will be run. They would then need to plant a specific file that would be used as part of the exploitation. What privileges could be gained by an attacker who successfully exploited this vulnerability? An attacker who successfully exploited this vulnerability could gain SYSTEM privileges. According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability? Successful exploitation of this vulnerability requires an attacker to take additional actions prior to exploitation to prepare the target environment. What are the fixed build numbers for the versions of Azure Site Recovery addressed in Update Rollup 76 for Azure Site Recovery? Component Name Version ASR V2A Agent (Classic VMware/Physical to Azure) 9.63.7233.1 ASR H2A Agent (Hyper-V or VMM to Azure) 5.1.8116.0 ASR Mars 2.0.9940.0 **Are there any any prerequisites for installing the update? To install Microsoft Azure Site Recovery Provider Update Rollup 76, you must have one of the following installed: Microsoft Azure Site Recovery Provider (version 5.23.x or a later version) Microsoft Azure Recovery Services Agent (version 2.0.9263.0 or a later version)

Affected Products (2)

Azure

  • Azure Agent for Site Recovery
  • Azure Agent for Backup

Security Updates (1)

Acknowledgments

R4nger & Zhiniang Peng with HUST

Revision History

  • 2025-03-11: Information published.
  • 2025-04-25: Updated acknowledgment. This is an informational change only.