Executive brief
Windows Admin Center, a browser-based management tool for managing Windows servers and infrastructure, contains a security flaw that could allow an authorized user to execute unauthorized commands. An attacker with low-level access to the system could exploit this to gain full control over the affected server. This could lead to a complete compromise of the system, including the theft of sensitive data or disruption of critical IT operations.
Technical details
An improper authorization vulnerability (CWE-285) exists in Microsoft Windows Admin Center. The flaw allows an attacker who is already authenticated to the local system with low-level privileges to bypass authorization checks and execute arbitrary code. The attack vector is local, meaning the attacker must have existing access to the host machine, but the exploit requires no user interaction and has a low complexity. Successful exploitation results in a total loss of confidentiality, integrity, and availability. Microsoft has addressed this in versions 2.7.4 and later.
Affected products
- Microsoft Windows Admin Center 1809.0 to 2.7.4
Timeline
- 2026-07-14: disclosed
- 2026-07-14: advisory