Elevation of Privilege Vulnerability in Azure Arc by Microsoft
CVE-2025-55316

7.8HIGH

Key Information:

Vendor

Microsoft

Vendor
CVE Published:
9 September 2025

What is CVE-2025-55316?

An external control of file name or path vulnerability in Azure Arc empowers unauthorized users to manipulate file paths, potentially leading to local privilege escalation. This flaw can be exploited by individuals with legitimate access, allowing them to gain higher privileges than should be permitted. Organizations utilizing Azure Arc should review Microsoft’s advisory to implement necessary mitigations and safeguard against potential exploitation.

Affected Version(s)

Azure Connected Machine Agent Unknown 1.0.0 < 1.56

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.