CVE-2025-21199 describes an improper privilege management vulnerability in the Microsoft Azure Agent Installer, allowing an authorized attacker to achieve local privilege escalation. With a CVSS score of 6.7 (Medium), exploitation requires low privileges and user interaction, but high attack complexity, potentially leading to high impact on confidentiality, integrity, and availability. While there is no known active exploitation, exploit code, or KEV listing, the vulnerability has garnered minimal community discussion and media coverage, with one article mentioning it in the context of Microsoft's March 2025 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.0.9940.0CPE matchmatch criteria | cpe:2.3:a:microsoft:azure_agent:*:*:*:*:*:backup:*:* | ||
< 9.30CPE matchmatch criteria | cpe:2.3:a:microsoft:azure_agent:*:*:*:*:*:site_recovery:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.