← CVE Tracker
7.8HIGH

CVE-2025-49692 — Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate…

Microsoft · Azure Connected Machine Agent · Published 9 Sept 2025 · Modified 1 Oct 2026

Description

Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally.

References

What to do
  1. Check whether Azure Connected Machine Agent is in your asset inventory.
  2. Patch in the next maintenance window; prioritise internet-facing systems.
  3. Record the decision in your risk register for audit evidence.
Alert me on similar CVEs →
Share

Link: adminadda.com/cve/CVE-2025-49692