Impact
The CVE describes a missing authentication requirement for a critical function in Microsoft PC Manager, a weakness categorized as CWE‑306 (Missing Authentication Controls). This flaw allows an attacker who already has authorized access to the application to elevate privileges locally, potentially running code with higher permissions. The impact is a privilege escalation that can lead to compromise of the host system.
Affected Systems
Microsoft PC Manager is the affected product. Specific affected version information is not listed in the advisory; therefore all installations are considered vulnerable until the patch is applied.
Risk and Exploitability
The vulnerability has a CVSS score of 7.8, indicating high severity. Its EPSS score is below 1% and it is not listed in CISA’s KEV catalog, suggesting limited publicly known exploitation. The likely attack vector is local; an attacker with authorized access to PC Manager can exploit the missing authentication in the privileged function to elevate privileges. The risk remains significant for systems that have not applied a fix.
OpenCVE Enrichment