CVE-2026-21224
published 2026-01-13CVE-2026-21224: Stack-based buffer overflow in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
PriorityP350high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.30%
22.3th percentile
Stack-based buffer overflow in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | azure_connected_machine_agent | < 1.60 | 1.60 |
| microsoft | azure_connected_machine_agent | >= 1.0.0 < 1.60.03293.2680 | 1.60.03293.2680 |
| msrc | azure_connected_machine_agent | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
vendor_msrc7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9426-g97r-954q: Stack-based buffer overflow in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally
ghsa_unreviewed·2026-01-13
CVE-2026-21224 [HIGH] CWE-121 GHSA-9426-g97r-954q: Stack-based buffer overflow in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally
Stack-based buffer overflow in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
Microsoft
Azure Connected Machine Agent Elevation of Privilege Vulnerability
vendor_msrc·2026-01-13·CVSS 7.8
CVE-2026-21224 [HIGH] CWE-121 Azure Connected Machine Agent Elevation of Privilege Vulnerability
Azure Connected Machine Agent Elevation of Privilege Vulnerability
Description: Stack-based buffer overflow in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
FAQ: What privileges could be gained by an attacker who successfully exploited this vulnerability?
An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.
FAQ: According to the CVSS metric, the attack vector is local (AV:L). What does that mean for this vulnerability?
An attacker could trigger this vulnerability remotely by having valid permissions on the Azure Resource Manager (ARM) API to access the Azure Relay. In the worst case scenario, an attacker could locally trigger this vulnerability by running code as a lower-privileged user on the same computer
No detection rules found.
No public exploits indexed.
2026-01-13
Published