CVE-2025-58724
7.8Microsoft · Azure Connected Machine Agent
An improper access control flaw in the Microsoft Azure Connected Machine Agent allows a locally authenticated attacker to escalate privileges.
Executive summary
A local privilege escalation vulnerability in the Microsoft Azure Connected Machine Agent poses a significant risk to server security by allowing authorized users to gain unauthorized administrative access.
Vulnerability
This vulnerability is caused by improper access control (CWE-284) within the agent. It allows an attacker who already possesses low-level local access to the system to escalate their privileges to a higher level.
Business impact
The ability for a local user to elevate privileges represents a critical security failure, as it allows attackers to bypass intended security boundaries and potentially gain full control over the affected server. Given the CVSS score of 7.8, this vulnerability is classified as High severity. Successful exploitation could lead to unauthorized data access, system-wide configuration changes, and the potential for lateral movement within the broader Azure infrastructure.
Remediation
Immediate Action: Organizations should update the Azure Connected Machine Agent to version 1.57 or later across all managed environments immediately.
Proactive Monitoring: Security teams should monitor system access logs for anomalous activity, specifically focusing on unexpected privilege changes or unauthorized execution of administrative tasks by standard user accounts.
Compensating Controls: While there is no direct virtual patch for this local flaw, enforcing the principle of least privilege for local user accounts and restricting interactive login access to servers can limit the potential for an attacker to initiate the exploitation process.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the potential for complete system compromise via privilege escalation, the urgency of this remediation is high. IT administrators must prioritize the deployment of the updated agent version to all servers running the Azure Connected Machine Agent to eliminate this local attack vector and ensure the integrity of the managed infrastructure.