cbcvebase.
CVE-2025-49692
published 2025-09-09

CVE-2025-49692: Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally.

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally.

Affected

3 ranges
VendorProductVersion rangeFixed in
microsoftazure_connected_machine_agent< 1.491.49
microsoftazure_connected_machine_agent>= 1.0.0 < 1.491.49
msrcazure_connected_machine_agent