« Volver al listado

CVE-2025-21199

Estado: AnalizadaMedia (6.7)—

Improper privilege management in Azure Agent Installer allows an authorized attacker to elevate privileges locally.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-21199",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-21199",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2025-03-11T18:26:19.570414Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "secure@microsoft.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 6.7,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "LOW",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 0.8
      }
    ]
  },
  "affected": [
    {
      "source": "secure@microsoft.com",
      "affectedData": [
        {
          "vendor": "Microsoft",
          "product": "Azure Agent for Backup",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.0",
              "lessThan": "2.0.9940.0",
              "versionType": "custom"
            }
          ]
        },
        {
          "vendor": "Microsoft",
          "product": "Azure Agent for Site Recovery",
          "versions": [
            {
              "status": "affected",
              "version": "1.0.0",
              "lessThan": "9.30",
              "versionType": "custom"
            }
          ]
        }
      ]
    }
  ],
  "published": "2025-03-11T17:16:19.670",
  "references": [
    {
      "url": "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-21199",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "secure@microsoft.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "secure@microsoft.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-269"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Improper privilege management in Azure Agent Installer allows an authorized attacker to elevate privileges locally."
    },
    {
      "lang": "es",
      "value": "La administración incorrecta de privilegios en el instalador del agente de Azure permite que un atacante autorizado eleve los privilegios localmente."
    }
  ],
  "lastModified": "2026-06-17T08:42:45.203",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:microsoft:azure_agent:*:*:*:*:*:backup:*:*",
              "vulnerable": true,
              "matchCriteriaId": "10E372B1-99BC-4DBE-AC91-9D90969430B4",
              "versionEndExcluding": "2.0.9940.0"
            },
            {
              "criteria": "cpe:2.3:a:microsoft:azure_agent:*:*:*:*:*:site_recovery:*:*",
              "vulnerable": true,
              "matchCriteriaId": "B675A111-5EBD-4983-AEE9-6E23CF2F90FB",
              "versionEndExcluding": "9.30"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "secure@microsoft.com"
}