CVE-2025-55316: Azure Connected Machine Agent Elevation of Privilege Vulnerability

Overview

Severity
High (CVSS 7.8)
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Category
Elevation of Privilege
Exploit Status
Not Exploited
Exploitation Likelihood
Unlikely
Patch Tuesday
2025-Sep
Released
2025-09-09
Last Updated
2025-09-09
EPSS Score
0.15% (percentile: 36.2%)

Description

External control of file name or path in Azure Arc allows an authorized attacker to elevate privileges locally.

FAQ

**What privileges could be gained by an attacker who successfully exploited this vulnerability? ** An attacker can deploy VM Extensions on compromised Servers

Affected Products (1)

Azure

  • Azure Connected Machine Agent

Security Updates (1)

Acknowledgments

<a href="https://uk.linkedin.com/in/contact-sharan-p">Sharan Patil</a> with <a href="https://reversec.com/">REVERSEC</a>

Revision History

  • 2025-09-09: Information published.
  • 2025-09-09: Updated CVE title. This is an informational change only.