Executive brief
Azure Arc is Microsoft's service for managing and governing hybrid cloud infrastructure across on-premises, edge, and multicloud environments. This vulnerability allows an attacker with local access to escalate privileges to system level, potentially gaining complete control over managed resources and sensitive data.
Technical details
This is an elevation of privilege vulnerability in Azure Arc. The vulnerability requires local access to an affected system but allows an unprivileged attacker to gain elevated (system-level) permissions. The exact root cause and vulnerable component are not detailed in the available references, but the CVSS 10.0 score indicates complete compromise of confidentiality, integrity, and availability is possible. A patch is expected from Microsoft; detailed technical analysis requires access to the Microsoft Security Response Center advisory.
Affected products
- Microsoft Azure Arc <UNKNOWN>
Timeline
- 2026-09-17: disclosed