Executive brief
Windows Modern Device Management (MDM) is a Microsoft system component that manages device policies and security settings across enterprise environments. A missing authentication check in a critical MDM function allows an authorized local user to bypass security features that would normally restrict access, potentially leading to unauthorized configuration changes or policy violations on managed devices.
Technical details
This vulnerability is an authentication bypass in Windows Modern Device Management (MDM) that affects a critical function handling device policies or security controls. The root cause is missing or insufficient authentication validation on a privileged operation, allowing an authorized local attacker to circumvent intended access restrictions. The attack vector is local; an attacker with existing user-level access to the device can exploit this to bypass security features. The vulnerability requires local access but does not require elevated privileges or additional user interaction. An attacker can exploit this to modify device configurations, disable security controls, or violate policy restrictions intended by the MDM administrator. Microsoft has published security updates to address this issue.
Affected products
- Microsoft Windows Multiple Windows versions (exact versions pending Microsoft patch Tuesday confirmation)
Timeline
- 2026-09-08: disclosed
- 2026-09-08: advisory