Filtered by vendor Microsoft Subscriptions
Filtered by product Azure Arc Subscriptions
Total 3 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-58724 1 Microsoft 5 Azure, Azure Agent, Azure Arc and 2 more 2025-10-24 7.8 High
Improper access control in Azure Connected Machine Agent allows an authorized attacker to elevate privileges locally.
CVE-2025-26627 1 Microsoft 1 Azure Arc 2025-07-13 7 High
Improper neutralization of special elements used in a command ('command injection') in Azure Arc allows an authorized attacker to elevate privileges locally.
CVE-2022-38007 1 Microsoft 2 Azure Arc, Azure Guest Configuration 2025-03-11 7.8 High
Azure Guest Configuration and Azure Arc-enabled servers Elevation of Privilege Vulnerability