Improper Privilege Management in Azure Agent Installer by Microsoft
CVE-2025-21199

6.7MEDIUM

What is CVE-2025-21199?

The Azure Agent Installer is susceptible to improper privilege management, allowing an authorized attacker to escalate privileges locally. This vulnerability can lead to unauthorized access and control over critical system functions, posing a significant risk to the integrity of Azure environments.

Affected Version(s)

Azure Agent for Backup Unknown 1.0.0 < 2.0.9940.0

Azure Agent for Site Recovery Unknown 1.0.0 < 9.30

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.