CVE-2025-49692 describes an improper access control vulnerability within the Azure Windows Virtual Machine Agent, allowing an authenticated local attacker to achieve privilege escalation. This high-severity flaw (CVSS 7.8) requires local access and low privileges, but its successful exploitation grants full confidentiality, integrity, and availability impact on the affected system. While Microsoft has patched this vulnerability, there is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed on the CISA KEV catalog, suggesting no active exploitation. Community discussion and media coverage are minimal, with only one mention and one article referencing its fix in a past Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.49CPE matchmatch criteria | cpe:2.3:a:microsoft:azure_connected_machine_agent:*:*:*:*:*:*:*:* | ||
>= 1.0.0, < 1.49CPE match | cpe:2.3:a:microsoft:azure_connected_machine_agent:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.