Improper neutralization of special elements used in a command (‘command injection’) in Azure Arc allows an authorized attacker to elevate privileges locally.
CVE-2025-26627 Azure Arc Installer Elevation of Privilege Vulnerability
Published March 11, 2025