Executive brief
A privilege escalation vulnerability exists in Windows Admin Center, a browser-based management tool used to administer Windows servers and infrastructure. An attacker with basic user access could exploit this flaw to gain higher-level administrative permissions across the network. This could lead to unauthorized access to sensitive server data, system configuration changes, or a complete takeover of managed infrastructure.
Technical details
A privilege escalation vulnerability (CWE-284) exists in Microsoft Windows Admin Center due to improper access control mechanisms. The flaw is reachable over the network and requires low-privileged authentication (PR:L) to exploit. By successfully exploiting this vulnerability, an attacker can bypass intended permission restrictions to gain elevated privileges (High Confidentiality, Integrity, and Availability impact). The attack vector is network-based and does not require user interaction. Microsoft has released information regarding this vulnerability in their Security Update Guide.
Affected products
- Microsoft Windows Admin Center
Timeline
- 2026-05-12: disclosed: Initial disclosure by Microsoft
- 2026-05-12: advisory: Microsoft Security Update Guide published