Filtered by vendor Microsoft Subscriptions
Filtered by product Azure Subscriptions
Total 10 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-49692 1 Microsoft 2 Azure, Azure Connected Machine Agent 2025-10-01 7.8 High
Improper access control in Azure Windows Virtual Machine Agent allows an authorized attacker to elevate privileges locally.
CVE-2025-55244 1 Microsoft 2 Azure, Azure Ai Bot Service 2025-09-25 9 Critical
Azure Bot Service Elevation of Privilege Vulnerability
CVE-2025-54914 1 Microsoft 1 Azure 2025-09-25 10 Critical
Azure Networking Elevation of Privilege Vulnerability
CVE-2025-55316 1 Microsoft 2 Azure, Azure Connected Machine Agent 2025-09-25 7.8 High
External control of file name or path in Azure Arc allows an authorized attacker to elevate privileges locally.
CVE-2025-49707 1 Microsoft 24 Azure, Azure Virtual Machine, Dcadsv5-series Azure Vm and 21 more 2025-09-17 7.9 High
Improper access control in Azure Virtual Machines allows an authorized attacker to perform spoofing locally.
CVE-2025-53767 1 Microsoft 2 Azure, Azure Openai 2025-09-17 10 Critical
Azure OpenAI Elevation of Privilege Vulnerability
CVE-2025-53792 1 Microsoft 2 Azure, Azure Portal 2025-09-17 9.1 Critical
Azure Portal Elevation of Privilege Vulnerability
CVE-2025-53763 1 Microsoft 1 Azure 2025-09-17 9.8 Critical
Improper access control in Azure Databricks allows an unauthorized attacker to elevate privileges over a network.
CVE-2025-53781 1 Microsoft 25 Azure, Azure Virtual Machine, Dcadsv5-series Azure Vm and 22 more 2025-09-17 7.7 High
Exposure of sensitive information to an unauthorized actor in Azure Virtual Machines allows an authorized attacker to disclose information over a network.
CVE-2019-0816 3 Canonical, Microsoft, Redhat 3 Ubuntu Linux, Azure, Enterprise Linux 2024-11-21 N/A
A security feature bypass exists in Azure SSH Keypairs, due to a change in the provisioning logic for some Linux images that use cloud-init, aka 'Azure SSH Keypairs Security Feature Bypass Vulnerability'.