Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2025-21199

Опубликовано: 11 мар. 2025
Источник: msrc
CVSS3: 6.7
EPSS Низкий

Описание

Azure Agent Installer for Backup and Site Recovery Elevation of Privilege Vulnerability

Improper privilege management in Azure Agent Installer allows an authorized attacker to elevate privileges locally.

FAQ

According to the CVSS metric, user interaction is required (UI:R). What does that mean for this vulnerability?

Successful exploitation of this vulnerability requires an administrator to install the VM agent on the target device where an attacker has planted specially crafted malicious files.

According to the CVSS metric, privileges required is low (PR:L). What does that mean for this vulnerability?

Successful exploitation of this vulnerability requires an attacker to have access to the location where the target file will be run. They would then need to plant a specific file that would be used as part of the exploitation.

What privileges could be gained by an attacker who successfully exploited this vulnerability?

An attacker who successfully exploited this vulnerability could gain SYSTEM privileges.

According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?

Successful exploitation of this vulnerability requires an attacker to take additional actions prior to exploitation to prepare the target environment.

What are the fixed build numbers for the versions of Azure Site Recovery addressed in Update Rollup 76 for Azure Site Recovery?

Component NameVersion
ASR V2A Agent (Classic VMware/Physical to Azure)9.63.7233.1
ASR H2A Agent (Hyper-V or VMM to Azure)5.1.8116.0
ASR Mars2.0.9940.0

**Are there any any prerequisites for installing the update?

To install Microsoft Azure Site Recovery Provider Update Rollup 76, you must have one of the following installed:

  • Microsoft Azure Site Recovery Provider (version 5.23.x or a later version)
  • Microsoft Azure Recovery Services Agent (version 2.0.9263.0 or a later version)

Обновления

ПродуктСтатьяОбновление
Azure Agent for Site Recovery
Azure Agent for Backup

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

DOS

N/A

EPSS

Процентиль: 31%
0.00154
Низкий

6.7 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.7
nvd
8 месяцев назад

Improper privilege management in Azure Agent Installer allows an authorized attacker to elevate privileges locally.

CVSS3: 6.7
github
8 месяцев назад

Improper privilege management in Azure Agent Installer allows an authorized attacker to elevate privileges locally.

CVSS3: 6.7
fstec
8 месяцев назад

Уязвимость установщика программного обеспечения для резервного копирования данных Azure Agent for Backup и программного обеспечения для репликации и аварийного восстановления Azure Agent for Site Recovery, позволяющая нарушителю повысить свои привилегии до уровня system

EPSS

Процентиль: 31%
0.00154
Низкий

6.7 Medium

CVSS3