Executive brief
A security vulnerability in Microsoft PC Manager, a tool used for system maintenance and optimization, could allow a user with limited access to gain full administrative control over a computer. This flaw stems from a failure to verify user identity before performing sensitive system tasks. An attacker who already has basic access to the machine could exploit this to bypass security restrictions, potentially leading to unauthorized data access or system-wide changes.
Technical details
A privilege escalation vulnerability exists in Microsoft PC Manager due to missing authentication for a critical function (CWE-306). The flaw allows a locally authenticated attacker with low privileges to execute sensitive operations that should be restricted to administrative users. By interacting with the vulnerable component, an attacker can achieve SYSTEM-level privileges on the affected host. The attack requires local access but no user interaction. Microsoft has released security updates to address this issue via the MSRC update guide.
Affected products
- Microsoft PC Manager
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory