CVE-2022-38007: high-severity vulnerability in Microsoft Azure Guest Configuration
Azure Guest Configuration and Azure Arc-enabled servers Elevation of Privilege Vulnerability
Published · Updated
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7.8epss 0.7%
exploitation probability
0.7%top 49% of all CVEs
observed exploitation
nono source reports it
Azure Guest Configuration and Azure Arc-enabled servers Elevation of Privilege Vulnerability
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
Related CVEs — Microsoft Azure Guest Configuration
In the same product, most dangerous first.
CVE-2026-24302HIGHAzure Arc Elevation of Privilege VulnerabilityEPSS 1.5%CVE-2025-26627HIGHAzure Arc Installer Elevation of Privilege VulnerabilityEPSS 0.9%CVE-2026-69555CRITICALAzure Arc Elevation of Privilege VulnerabilityEPSS 0.8%CVE-2026-70009CRITICALAzure Arc Elevation of Privilege VulnerabilityEPSS 0.5%CVE-2026-69399CRITICALAzure Arc Elevation of Privilege VulnerabilityEPSS 0.5%