Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2025-47989

CVE-2025-47989: Azure Connected Machine Agent Privilege Escalation

CVE-2025-47989 is a privilege escalation vulnerability in Microsoft Azure Connected Machine Agent caused by improper access control. Authorized attackers can exploit this flaw to gain elevated privileges locally on affected systems.

Published:

CVE-2025-47989 Overview

CVE-2025-47989 is an improper access control vulnerability [CWE-284] in the Microsoft Azure Connected Machine Agent. An authorized local attacker can exploit weak access controls to elevate privileges on the affected host. Microsoft published the advisory on October 14, 2025.

The Azure Connected Machine Agent extends Azure management capabilities to non-Azure servers, including on-premises and multi-cloud Windows and Linux machines. A successful exploit allows a low-privileged local user to gain higher privileges, undermining the trust boundary between standard users and system-level components on Arc-enabled servers.

Critical Impact

A local authenticated attacker can elevate to higher privileges on any server running a vulnerable Azure Connected Machine Agent, gaining full confidentiality, integrity, and availability impact.

Affected Products

  • Microsoft Azure Connected Machine Agent (Windows and Linux distributions)
  • Azure Arc-enabled servers using vulnerable agent versions
  • Hybrid and multi-cloud endpoints onboarded via Azure Arc

Discovery Timeline

  • 2025-10-14 - CVE-2025-47989 published to the National Vulnerability Database
  • 2025-10-14 - Microsoft released the CVE-2025-47989 Update Guide
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-47989

Vulnerability Analysis

The vulnerability is categorized as Improper Access Control [CWE-284] within the Azure Connected Machine Agent. The agent runs privileged operations on the host to manage inventory, extensions, and machine configuration on behalf of Azure. Insufficient enforcement of access restrictions on one or more agent components allows a local user with limited rights to interact with privileged functionality intended only for higher-privileged contexts.

Exploitation requires local access and valid low-privilege credentials on the host. The attack complexity is rated High, indicating the attacker must satisfy specific preconditions or win a race window before the agent enforces or resets the intended access boundary. No user interaction is required.

A successful exploit yields high impact to confidentiality, integrity, and availability. The attacker can execute actions in the security context of the agent, which typically runs with elevated privileges, enabling code execution, tampering with agent-managed configuration, and pivoting into Azure resources reachable via the machine's managed identity.

Root Cause

The root cause is improper enforcement of access controls on privileged resources managed by the Azure Connected Machine Agent. Components accessible to local unprivileged users do not sufficiently validate the caller before performing privileged operations, allowing crossing of the user-to-system trust boundary. Microsoft has not published low-level technical details in the public advisory.

Attack Vector

The attack vector is local. An attacker who has authenticated to the host as a standard user targets the agent's privileged interface, service, or file resource. By invoking exposed functionality that lacks adequate access checks, the attacker executes actions as a higher-privileged principal. The scope remains unchanged, meaning the impact stays within the compromised security authority.

On Arc-enabled servers the agent brokers access to the machine's Azure identity. Post-exploitation, the attacker may abuse the associated managed identity to reach Azure control-plane resources reachable from the compromised host. Refer to the Microsoft CVE-2025-47989 Update Guide for authoritative details.

Detection Methods for CVE-2025-47989

Indicators of Compromise

  • Unexpected child processes spawned by himds.exe, gc_service, or azcmagent with SYSTEM or root privileges.
  • Modifications to agent configuration files under %ProgramData%\AzureConnectedMachineAgent\ or /var/opt/azcmagent/ by non-administrative users.
  • Unusual invocations of azcmagent subcommands from low-privilege user sessions.
  • New or modified scheduled tasks, systemd units, or extension installations initiated outside normal Azure Arc management activity.

Detection Strategies

  • Monitor for privilege transitions where a standard user account triggers agent processes that then execute code as SYSTEM or root.
  • Alert on writes to agent binaries, extension directories, and configuration paths originating from non-service accounts.
  • Correlate local process telemetry with Azure activity logs showing agent-driven changes not initiated by an administrator.

Monitoring Recommendations

  • Ingest Azure Arc agent logs (azcmagent.log, himds.log, extension logs) into a centralized SIEM for behavioral analysis.
  • Baseline normal agent behavior on each server and alert on deviations such as new extension installs or off-hours activity.
  • Track managed identity token issuance and downstream Azure API calls from Arc-enabled machines to identify post-exploitation reuse.

How to Mitigate CVE-2025-47989

Immediate Actions Required

  • Apply the fixed Azure Connected Machine Agent version specified in the Microsoft CVE-2025-47989 Update Guide to all Arc-enabled servers.
  • Inventory all hosts running the agent using azcmagent show and Azure Resource Graph queries against Microsoft.HybridCompute/machines.
  • Restrict interactive and remote logon rights on Arc-enabled servers to reduce the pool of local users who could exploit the flaw.
  • Review permissions assigned to managed identities of Arc-enabled machines and apply least privilege.

Patch Information

Microsoft addresses CVE-2025-47989 in an updated release of the Azure Connected Machine Agent. Consult the Microsoft CVE-2025-47989 Update Guide for the minimum fixed version applicable to your platform. Update the agent on Windows via the MSI installer or automatic update channel, and on Linux via the distribution package manager pointing at the Microsoft repository.

Workarounds

  • No official workaround is published; patching is the required remediation.
  • Limit local logon on Arc-enabled hosts to trusted administrators until the patched agent is deployed.
  • Enable automatic agent upgrades in Azure Arc to receive future security fixes promptly.
  • Segment Arc-enabled machines and constrain managed identity role assignments to minimize downstream impact if a host is compromised.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.