6.7
CVE-2025-21199
- EPSS 0.08%
- Veröffentlicht 11.03.2025 16:59:06
- Zuletzt bearbeitet 07.07.2025 17:18:36
- Quelle secure@microsoft.com
- CVE-Watchlists
- Unerledigt
Azure Agent Installer for Backup and Site Recovery Elevation of Privilege Vulnerability
Improper privilege management in Azure Agent Installer allows an authorized attacker to elevate privileges locally.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Azure Agent SwPlatformbackup Version < 2.0.9940.0
Microsoft ≫ Azure Agent SwPlatformsite_recovery Version < 9.30
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.08% | 0.234 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| secure@microsoft.com | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
|
CWE-269 Improper Privilege Management
The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.