Description
External control of file name or path in Azure Arc allows an authorized attacker to elevate privileges locally.
Problem types
CWE-73: External Control of File Name or Path
Product status
References
msrc.microsoft.com/update-guide/vulnerability/CVE-2025-55316 (Azure Connected Machine Agent Elevation of Privilege Vulnerability)