Skip to content

Commit 2d3abfd

Browse files
Merge pull request #312916 from RochakSingh-blr/automation-security-update-windows-hybrid-worker-extension
Azure Automation Windows Hybrid Worker Extension (1.3.74) security update
2 parents 07341d2 + a630b27 commit 2d3abfd

1 file changed

Lines changed: 11 additions & 1 deletion

File tree

articles/automation/whats-new.md

Lines changed: 11 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -4,7 +4,7 @@ description: Significant updates to Azure Automation updated each month.
44
services: automation
55
ms.subservice:
66
ms.topic: overview
7-
ms.date: 08/12/2025
7+
ms.date: 03/10/2026
88
ms.custom: references_regions
99
ms.author: v-rochak2
1010
author: RochakSingh-blr
@@ -23,6 +23,16 @@ Azure Automation receives improvements on an ongoing basis. To stay up to date w
2323

2424
This page is updated monthly, so revisit it regularly. If you're looking for items older than six months, you can find them in [Archive for What's new in Azure Automation](whats-new-archive.md).
2525

26+
## March 2026
27+
28+
### Security Update: Azure Automation Windows Hybrid Worker Extension (1.3.74)
29+
30+
Windows Hybrid Worker Extension Version 1.3.74 includes a security improvement that strengthens access controls for communication with Hybrid Instance Metadata Service (HIMDS).
31+
32+
Under specific startup timing conditions, the Windows Hybrid Worker Extension tries to connect to HIMDS before the service is fully initialized. In this narrow window, a local nonprivileged process can impersonate the metadata service endpoint and gain unauthorized read access to protected metadata or configuration information.
33+
34+
This release addresses the issue by adding an extra validation to ensure that it connects only to trusted, system owned metadata endpoints. These changes enhance protection of system metadata and configuration information by ensuring access is limited to trusted system components.
35+
2636
## August 2025
2737

2838
### Deployment resumption: Azure Automation revised Service and Subscription limits

0 commit comments

Comments
 (0)