Executive brief
A critical vulnerability exists in Microsoft Azure Local Disconnected Operations, a service used to manage hybrid cloud environments when they are not connected to the internet. An unauthorized attacker could exploit this flaw over the network to gain full administrative control over the system. This could lead to the complete compromise of customer data, unauthorized access to sensitive operations, and total disruption of the affected infrastructure.
Technical details
A vulnerability classified as improper authentication (CWE-287) exists within the Azure Local Disconnected Operations component. The flaw allows a remote, unauthenticated attacker to bypass security checks and elevate their privileges to a higher level, potentially reaching administrative status. The attack can be carried out over a network without any user interaction or prior credentials. Given the CVSS score of 10.0 and the 'Changed' scope (S:C), an exploit could allow the attacker to move beyond the immediate component to impact other parts of the environment. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Azure Local Disconnected Operations
Timeline
- 2026-05-18: advisory: Initial advisory published by Microsoft and NVD.
- 2026-05-18: patched: Security updates made available via Microsoft Security Update Guide.