CVE-2025-55316
7.8Microsoft · Azure Connected Machine Agent
A path traversal vulnerability in the Microsoft Azure Connected Machine Agent allows an authorized local attacker to elevate privileges.
Executive summary
A high-severity path traversal vulnerability in the Microsoft Azure Connected Machine Agent allows local attackers to elevate privileges, necessitating immediate patching.
Vulnerability
The vulnerability is identified as a CWE-73: External Control of File Name or Path flaw. It allows an authorized attacker with local access to manipulate file paths to achieve privilege escalation on the host system.
Business impact
The ability for a local attacker to escalate privileges presents a significant risk to the integrity and confidentiality of the host environment. Given the CVSS score of 7.8, this flaw is categorized as High severity, as it could permit an attacker to gain administrative control over the affected machine, potentially leading to full system compromise and lateral movement within the Azure infrastructure.
Remediation
Immediate Action: Update the Microsoft Azure Connected Machine Agent to version 1.56 or later immediately to resolve the path validation flaw.
Proactive Monitoring: Review system logs for unauthorized file access attempts or suspicious process execution patterns originating from the agent service.
Compensating Controls: Ensure that the principle of least privilege is strictly enforced for local user accounts to limit the potential for exploitation by unauthorized or low-privileged actors.
Exploitation status
Public Exploit Available: No (exploit_available is false).
Analyst recommendation
This vulnerability represents a serious security gap that could allow an attacker to bypass local security boundaries. IT administrators should prioritize the deployment of the updated agent across all managed instances, as patching is the only definitive way to mitigate the risk of local privilege escalation.