Executive brief
The Azure Connected Machine Agent, which manages non-Azure servers for use with Azure services, contains a security flaw in how it manages permissions. An attacker who already has low-level access to a server could exploit this to gain full administrative control over the machine. This could lead to unauthorized data access, system-wide changes, or the disruption of critical services.
Technical details
An improper access control vulnerability (CWE-284) exists in the Microsoft Azure Connected Machine Agent. The flaw allows a local attacker with low-privileged user access to bypass security restrictions and elevate their privileges to a higher level, such as SYSTEM or root. The attack vector is local, requiring the attacker to already have an authenticated session on the target host. Successful exploitation grants the attacker full confidentiality, integrity, and availability impact over the affected system. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Azure Connected Machine Agent
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory