Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-27334 | Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally. |
Wed, 01 Oct 2025 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:microsoft:azure_connected_machine_agent:*:*:*:*:*:*:*:* |
Thu, 11 Sep 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft
Microsoft azure Microsoft azure Connected Machine Agent |
|
| Vendors & Products |
Microsoft
Microsoft azure Microsoft azure Connected Machine Agent |
Tue, 09 Sep 2025 23:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 09 Sep 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally. | |
| Title | Azure Connected Machine Agent Elevation of Privilege Vulnerability | |
| Weaknesses | CWE-284 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: microsoft
Published:
Updated: 2026-02-26T17:48:55.778Z
Reserved: 2025-06-09T19:59:44.873Z
Link: CVE-2025-49692
Updated: 2025-09-09T17:44:20.440Z
Status : Undergoing Analysis
Published: 2025-09-09T17:15:47.843
Modified: 2025-10-01T20:30:30.897
Link: CVE-2025-49692
No data.
OpenCVE Enrichment
Updated: 2025-09-11T10:43:07Z
EUVD