Impact
The vulnerability is an improper access control flaw in Microsoft Windows Admin Center that permits an attacker who already has legitimate local access to increase privileges on the host. This issue is identified by CWE-284 and can allow the attacker to perform actions that require higher privileges, potentially compromising system security and data integrity. The vulnerability does not affect remote attackers directly unless they have first gained local credentials.
Affected Systems
Microsoft Windows Admin Center is the only product directly impacted by this vulnerability. No specific version ranges were published in the CNA data, so any deployment of Windows Admin Center that has not applied the latest security updates may be vulnerable.
Risk and Exploitability
The CVSS score of 7.8 indicates a high severity, while the EPSS score of less than 1% suggests the exploitation probability is currently low. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector requires an attacker to be already authenticated to the local Windows system that hosts Windows Admin Center; from that position, the attacker can exploit the access control flaw to elevate privileges. No public exploits are documented, but the presence of a high CVSS score and existing access would make it a suitable target for insider threats or an attacker who has compromised a user account.
OpenCVE Enrichment