CVE-2025-55316 describes a local privilege escalation vulnerability in the Microsoft Azure Connected Machine Agent, stemming from external control of file names or paths (CWE-73). With a CVSS score of 7.8 (HIGH), an authorized local attacker can achieve high confidentiality, integrity, and availability impacts without user interaction. While the EPSS score is low and it's not in the KEV catalog, indicating no known active exploitation, there is no public exploit code available (Metasploit, Nuclei, ExploitDB). However, it has garnered some community discussion and media coverage, including a mention in a BleepingComputer article regarding Microsoft's September 2025 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.56CPE matchmatch criteria | cpe:2.3:a:microsoft:azure_connected_machine_agent:*:*:*:*:*:*:*:* | ||
>= 1.0.0, < 1.56CPE match | cpe:2.3:a:microsoft:azure_connected_machine_agent:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.