CVE-2026-69543: Azure Virtual Machines Elevation of Privilege Vulnerability
Azure Virtual Machines Elevation of Privilege Vulnerability
Other sources
Server-side request forgery (ssrf) in Azure Virtual Machines allows an authorized attacker to elevate privileges over a network.
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The attacker must already be authorized and have low privileges. Exploitation can be performed over the network and does not require user interaction.
What is the potential impact if exploitation succeeds?
Successful exploitation allows elevation of privilege. The published vector indicates high potential impact to confidentiality, integrity, and availability, including across a security scope boundary.
Is there a known workaround or indication that default Azure Virtual Machines configurations are affected?
The provided information does not identify a workaround, affected configuration details, or whether default deployments are vulnerable. Consult the referenced Microsoft advisory for remediation and exposure guidance.