Executive brief
Windows Admin Center, a browser-based management tool for Windows servers and clusters, contains a security flaw that allows an existing user to gain higher-level administrative permissions. An attacker with low-level access could exploit this over the network to take control of sensitive management functions or access restricted data. This could lead to unauthorized configuration changes or a broader compromise of the managed server infrastructure.
Technical details
An improper authentication vulnerability (CWE-287) exists in Microsoft Windows Admin Center. The flaw allows a remote attacker with low-privileged user credentials to bypass authentication checks and elevate their privileges within the management console. The attack is carried out over the network and does not require user interaction. Successful exploitation grants the attacker high-level confidentiality and integrity impacts, potentially allowing full administrative control over the managed environment. Microsoft has addressed this in versions starting from 2.7.4.
Affected products
- Microsoft Windows Admin Center 1809.0 to 2.7.4
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory