Description
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
Problem types
CWE-284: Improper Access Control
Product status
References
msrc.microsoft.com/update-guide/vulnerability/CVE-2025-58724 (Arc Enabled Servers - Azure Connected Machine Agent Elevation of Privilege Vulnerability)