Executive brief
A security vulnerability exists in the Windows Server Update Service (WSUS), a tool used by IT administrators to manage and distribute software updates across a corporate network. An attacker with basic user access to the network could exploit this flaw to gain higher-level administrative privileges. This could allow them to take control of the update process or compromise other systems on the network.
Technical details
A privilege escalation vulnerability exists in Windows Server Update Service (WSUS) due to missing authentication for a critical function (CWE-306). An attacker who is already authenticated to the network with low-privileged credentials can exploit this over the network without any user interaction. Successful exploitation allows the attacker to elevate their privileges, potentially gaining administrative control over the update infrastructure. Microsoft has released security updates for various versions of Windows 10 and Windows Server (2012 through 2019) to address this issue.
Affected products
- Microsoft Windows Server Update Service (WSUS) Windows 10, Windows Server 2012, 2016, 2019
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory