Executive brief
Windows Admin Center is a browser-based management tool used by IT administrators to manage Windows servers and infrastructure. A security flaw in this tool allows an attacker who already has basic access to the network to gain higher-level administrative permissions. This could allow an unauthorized user to take control of managed servers, potentially leading to data theft or service disruptions.
Technical details
A missing authorization vulnerability (CWE-862) exists in Microsoft Windows Admin Center. The flaw allows an authenticated attacker with low-level privileges to bypass authorization checks over the network. By exploiting this issue, the attacker can elevate their privileges to a higher level within the management console. This could lead to unauthorized configuration changes or full administrative control over the managed environment. Microsoft has addressed this in version 2511.
Affected products
- Microsoft Windows Admin Center versions up to (excluding) 2511
Timeline
- 2026-05-12: advisory: Initial disclosure by Microsoft
- 2026-05-28: other: NVD analysis and CPE information added