Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-49692

26
FAUCET Score

CVE-2025-49692 describes an improper access control vulnerability within the Azure Windows Virtual Machine Agent, allowing an authenticated local attacker to achieve privilege escalation. This high-severity flaw (CVSS 7.8) requires local access and low privileges, but its successful exploitation grants full confidentiality, integrity, and availability impact on the affected system. While Microsoft has patched this vulnerability, there is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), and it is not listed on the CISA KEV catalog, suggesting no active exploitation. Community discussion and media coverage are minimal, with only one mention and one article referencing its fix in a past Patch Tuesday.

Impacted Technologies

VendorProductVersion(s)CPE
< 1.49CPE matchmatch criteria
cpe:2.3:a:microsoft:azure_connected_machine_agent:*:*:*:*:*:*:*:*
>= 1.0.0, < 1.49CPE match
cpe:2.3:a:microsoft:azure_connected_machine_agent:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.32%
Probability of exploitation in next 30 days
EPSS Percentile
24.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0032 is in the 62nd percentile among its peer group of 17,070 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

microsoftpatch availablevia msrc
Product: Azure Connected Machine AgentFixed in: 1.49
View patch
microsoftvendor investigatingvia nvd_reference
View patch

Vendor Advisories (1)

microsoft2025-Sep/CVE-2025-49692Important

Azure Connected Machine Agent Elevation of Privilege Vulnerability

Sep 9, 2025

References

msrc.microsoft.com / update-guide/vulnerability/CVE-2025-49692
Vendor Advisory