📦 Azure Connected Machine Agent

by Microsoft

🔍 What is Azure Connected Machine Agent?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-21224

HIGH CVSS 7.8 Jan 13, 2026

A stack-based buffer overflow vulnerability in Azure Connected Machine Agent allows authenticated attackers to execute arbitrary code with elevated privileges on affected systems. This affects organiz...

CVE-2025-58724

HIGH CVSS 7.8 Oct 14, 2025

This vulnerability in Azure Connected Machine Agent allows authenticated attackers to escalate privileges on local systems. Attackers with existing access can gain higher permissions, potentially comp...

CVE-2025-47989

HIGH CVSS 7.0 Oct 14, 2025

This vulnerability in Azure Connected Machine Agent allows an authenticated attacker with local access to a machine to escalate privileges, potentially gaining administrative control. It affects syste...

CVE-2025-49692

HIGH CVSS 7.8 Sep 9, 2025

An improper access control vulnerability in Azure Windows Virtual Machine Agent allows authenticated attackers to escalate privileges locally on affected systems. This affects Azure Windows Virtual Ma...

CVE-2024-38162

HIGH CVSS 7.8 Aug 13, 2024

This vulnerability allows an authenticated attacker with local access to elevate privileges on Azure Arc-enabled servers. It affects systems running the Azure Connected Machine Agent (Azure Arc agent)...

CVE-2024-38098

HIGH CVSS 7.8 Aug 13, 2024

This vulnerability allows an authenticated attacker with local access to elevate privileges on Azure Arc-enabled servers. Attackers could gain SYSTEM-level privileges by exploiting improper handling o...

CVE-2023-35624

HIGH CVSS 7.3 Dec 12, 2023

This vulnerability in Azure Connected Machine Agent allows an authenticated attacker to elevate privileges on affected systems. Attackers could gain SYSTEM-level access on Windows machines or root acc...