Azure Connected Machine Agent
by Microsoft
CVEs (12)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-40381 | Hig | 0.51 | 7.8 | 0.00 | May 12, 2026 | Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-26117 | Hig | 0.51 | 7.8 | 0.00 | Mar 10, 2026 | Authentication bypass using an alternate path or channel in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-21224 | Hig | 0.51 | 7.8 | 0.00 | Jan 13, 2026 | Stack-based buffer overflow in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-58724 | Hig | 0.51 | 7.8 | 0.01 | Oct 14, 2025 | Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-55316 | Hig | 0.51 | 7.8 | 0.00 | Sep 9, 2025 | External control of file name or path in Azure Arc allows an authorized attacker to elevate privileges locally. | ||
| CVE-2025-49692 | Hig | 0.51 | 7.8 | 0.00 | Sep 9, 2025 | Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally. | ||
| CVE-2024-38162 | Hig | 0.51 | 7.8 | 0.01 | Aug 13, 2024 | Azure Connected Machine Agent Elevation of Privilege Vulnerability | ||
| CVE-2024-38098 | Hig | 0.51 | 7.8 | 0.01 | Aug 13, 2024 | Azure Connected Machine Agent Elevation of Privilege Vulnerability | ||
| CVE-2024-21329 | Hig | 0.48 | 7.3 | 0.01 | Feb 13, 2024 | Azure Connected Machine Agent Elevation of Privilege Vulnerability | ||
| CVE-2023-35624 | Hig | 0.48 | 7.3 | 0.01 | Dec 12, 2023 | Azure Connected Machine Agent Elevation of Privilege Vulnerability | ||
| CVE-2025-47989 | Hig | 0.46 | 7.0 | 0.01 | Oct 14, 2025 | Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-47632 | Hig | 0.00 | 8.8 | 0.00 | Jul 14, 2026 | Improper certificate validation in Azure Monitor Agent allows an unauthorized attacker to elevate privileges over an adjacent network. |
- risk 0.51cvss 7.8epss 0.00
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Authentication bypass using an alternate path or channel in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Stack-based buffer overflow in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.01
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
External control of file name or path in Azure Arc allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.00
Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally.
- risk 0.51cvss 7.8epss 0.01
Azure Connected Machine Agent Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
Azure Connected Machine Agent Elevation of Privilege Vulnerability
- risk 0.48cvss 7.3epss 0.01
Azure Connected Machine Agent Elevation of Privilege Vulnerability
- risk 0.48cvss 7.3epss 0.01
Azure Connected Machine Agent Elevation of Privilege Vulnerability
- risk 0.46cvss 7.0epss 0.01
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 8.8epss 0.00
Improper certificate validation in Azure Monitor Agent allows an unauthorized attacker to elevate privileges over an adjacent network.