cbcvebase.
CVE-2026-21224
published 2026-01-13

CVE-2026-21224: Stack-based buffer overflow in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
Stack-based buffer overflow in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.

Affected

3 ranges
VendorProductVersion rangeFixed in
microsoftazure_connected_machine_agent< 1.601.60
microsoftazure_connected_machine_agent>= 1.0.0 < 1.60.03293.26801.60.03293.2680
msrcazure_connected_machine_agent