cbcvebase.
CVE-2025-47989
published 2025-10-14

CVE-2025-47989: Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.

high7CVSS 3.1
AVLACHPRLUINSUCHIHAH
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.

Affected

3 ranges
VendorProductVersion rangeFixed in
microsoftarc_enabled_servers_azure_connected_machine_agent>= 1.0.0 < 1.571.57
microsoftazure_connected_machine_agent< 1.571.57
msrcarc_enabled_servers_azure_connected_machine_agent