Improper Privilege Management in Azure Agent Installer by Microsoft
CVE-2025-21199
6.7MEDIUM
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 11 March 2025
What is CVE-2025-21199?
The Azure Agent Installer is susceptible to improper privilege management, allowing an authorized attacker to escalate privileges locally. This vulnerability can lead to unauthorized access and control over critical system functions, posing a significant risk to the integrity of Azure environments.
Affected Version(s)
Azure Agent for Backup Unknown 1.0.0 < 2.0.9940.0
Azure Agent for Site Recovery Unknown 1.0.0 < 9.30
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved