Microsoft Azure MCP Server Tools是美国微软(Microsoft)公司的一个模型上下文协议,并支持各种工具、语言和框架,可以在Azure上构建和部署应用程序。 Microsoft Azure MCP Server Tools存在代码问题漏洞。攻击者利用该漏洞可以提升权限。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Microsoft | Azure MCP Server Tools 1.0.0 (npm) | 1.0.0< 1.0.2 |
affected |
| Microsoft | Azure MCP Server Tools 1.0.0 (NuGet) | 1.0.0< 1.0.2 |
affected |
| Microsoft | Azure MCP Server Tools 2.0.0 (npm) | 2.0.0-beta.1< 2.0.0-beta.17 |
affected |
| Microsoft | Azure MCP Server Tools 2.0.0 (NuGet) | 2.0.0-beta.1< 2.0.0-beta.17 |
affected |
| Microsoft | Azure MCP Server Tools 2.0.0 (PyPi) | 2.0.0-beta.1< 2.0.0-beta.17 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Microsoft | Azure MCP Server Tools 1.0.0 (npm) | 1.0.0 ~ 1.0.2 | - |
|
| Microsoft | Azure MCP Server Tools 1.0.0 (NuGet) | 1.0.0 ~ 1.0.2 | - |
|
| Microsoft | Azure MCP Server Tools 2.0.0 (npm) | 2.0.0-beta.1 ~ 2.0.0-beta.17 | - |
|
| Microsoft | Azure MCP Server Tools 2.0.0 (NuGet) | 2.0.0-beta.1 ~ 2.0.0-beta.17 | - |
|
| Microsoft | Azure MCP Server Tools 2.0.0 (PyPi) | 2.0.0-beta.1 ~ 2.0.0-beta.17 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-25177 | 8.8 HIGH | Active Directory Domain Services Elevation of Privilege Vulnerability |
| CVE-2026-26106 | 8.8 HIGH | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-21262 | 8.8 HIGH | SQL Server Elevation of Privilege Vulnerability |
| CVE-2026-23669 | 8.8 HIGH | RPC Runtime Library Remote Code Execution Vulnerability |
| CVE-2026-23654 | 8.8 HIGH | GitHub: Zero Shot SCFoundation Remote Code Execution Vulnerability |
| CVE-2026-26116 | 8.8 HIGH | SQL Server Elevation of Privilege Vulnerability |
| CVE-2026-26115 | 8.8 HIGH | SQL Server Elevation of Privilege Vulnerability |
| CVE-2026-24283 | 8.8 HIGH | Multiple UNC Provider Kernel Driver Elevation of Privilege Vulnerability |
| CVE-2026-20967 | 8.8 HIGH | System Center Operations Manager (SCOM) Elevation of Privilege Vulnerability |
| CVE-2026-26114 | 8.8 HIGH | Microsoft SharePoint Server Remote Code Execution Vulnerability |
| CVE-2026-25188 | 8.8 HIGH | Windows Telephony Service Elevation of Privilege Vulnerability |
| CVE-2026-26113 | 8.4 HIGH | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-26110 | 8.4 HIGH | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2026-26109 | 8.4 HIGH | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2026-26148 | 8.1 HIGH | Microsoft Azure AD SSH Login extension for Linux Elevation of Privilege Vulnerability |
| CVE-2026-26105 | 8.1 HIGH | Microsoft SharePoint Server Spoofing Vulnerability |
| CVE-2026-25173 | 8.0 HIGH | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
| CVE-2026-25172 | 8.0 HIGH | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
| CVE-2026-26111 | 8.0 HIGH | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
| CVE-2026-24290 | 7.8 HIGH | Windows Projected File System Elevation of Privilege Vulnerability |
Showing top 20 of 78 CVEs. View all on vendor page → →
No comments yet