CVE-2025-47989
published 2025-10-14CVE-2025-47989: Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
PriorityP337high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
EPSS
0.51%
40.1th percentile
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | arc_enabled_servers_azure_connected_machine_agent | >= 1.0.0 < 1.57 | 1.57 |
| microsoft | azure_connected_machine_agent | < 1.57 | 1.57 |
| msrc | arc_enabled_servers_azure_connected_machine_agent | — | — |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_msrc7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-m3vx-vrp7-pf23: Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally
ghsa_unreviewed·2025-10-14
CVE-2025-47989 [HIGH] CWE-284 GHSA-m3vx-vrp7-pf23: Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
Microsoft
Arc Enabled Servers - Azure Connected Machine Agent Elevation of Privilege Vulnerability
vendor_msrc·2025-10-14·CVSS 7.0
CVE-2025-47989 [HIGH] CWE-284 Arc Enabled Servers - Azure Connected Machine Agent Elevation of Privilege Vulnerability
Arc Enabled Servers - Azure Connected Machine Agent Elevation of Privilege Vulnerability
Description: Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could an attacker gain with successful exploitation?
An attacker who successfully exploited the vulnerability could elevate their privileges as ‘NT AUTHORITY\SYSTEM’ user and perform arbitrary code execution.
FAQ: What actions do customers need to take to protect themselves from this vulnerability?
Customers should update their Azure Connected Machine Agent to the latest version. For more information, see What's new with Azure Connected Machine agent.
FAQ: According to the CVSS metric, the attack vector is local (AV:L) and privileges required is low
No detection rules found.
No public exploits indexed.
2025-10-14
Published