CVE-2025-58724: Arc Enabled Servers - Azure Connected Machine Agent Elevation of Privilege Vulnerability
Overview
- Severity
- High (CVSS 7.8)
- CVSS Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
- Category
- Elevation of Privilege
- Exploit Status
- Not Exploited
- Exploitation Likelihood
- Unlikely
- Patch Tuesday
- 2025-Oct
- Released
- 2025-10-14
- Last Updated
- 2025-10-15
- EPSS Score
- 0.05% (percentile: 17.2%)
Description
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
FAQ
What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
Affected Products (1)
Azure
- Arc Enabled Servers - Azure Connected Machine Agent
Security Updates (2)
Acknowledgments
<a href="https://uk.linkedin.com/in/contact-sharan-p">Sharan Patil</a> with <a href="https://reversec.com/">REVERSEC</a>
Revision History
- 2025-10-14: Information published.
- 2025-10-15: Affected software updated with new package information.