Executive brief
Windows Enterprise App Management is a Microsoft system component that manages application deployment and configuration in enterprise environments. This vulnerability allows an authorized local user to escalate their privileges to a higher level of system access, potentially enabling them to take full control of the device or access sensitive business data.
Technical details
The vulnerability is a privilege escalation flaw caused by improper validation of permissions or privilege levels in Windows Enterprise App Management. An attacker with local access to an affected system can exploit this to elevate their privileges locally. The attack requires authentication or local access to trigger, and successful exploitation grants elevated system privileges. Patches are expected to be available from Microsoft through their security update channels.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed