cbcvebase.
CVE-2025-55316
published 2025-09-09

CVE-2025-55316: External control of file name or path in Azure Arc allows an authorized attacker to elevate privileges locally.

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
External control of file name or path in Azure Arc allows an authorized attacker to elevate privileges locally.

Affected

3 ranges
VendorProductVersion rangeFixed in
microsoftazure_connected_machine_agent< 1.561.56
microsoftazure_connected_machine_agent>= 1.0.0 < 1.561.56
msrcazure_connected_machine_agent