CVE-2025-27489HighCVSS 7.8
Azure Local Elevation of Privilege Vulnerability
🔗 CVE IDs covered (1)
📋 Description
Improper input validation in Azure Local allows an authorized attacker to elevate privileges locally.
🎯 Affected products2
- Azure Stack HCI OS 22H2
- Azure Stack HCI OS 23H2
✅ Remediation
KB5055526 (Security Update) — fixed build 10.0.20348.3328 KBRelease Notes (Security Update) — fixed build 10.0.25398.1486
🔗 References (5)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-27489
- patchhttps://support.microsoft.com/en-us/topic/release-notes-for-azure-stack-hci-version-22h2-fea63106-a0a9-4b6c-bb72-a07985c98a56
- referencehttps://support.microsoft.com/help/5055526
- patchhttps://learn.microsoft.com/en-us/azure-stack/hci/update/about-updates-23h2
- referencehttps://learn.microsoft.com/en-us/azure/azure-local/release-information-23h2?view=azloc-2503