Impact
Missing authentication for a critical function in Microsoft PC Manager allows an authorized attacker to elevate privileges locally. The lack of required credentials enables an attacker with access to PC Manager to gain higher level permissions than intended.
Affected Systems
Microsoft PC Manager is the affected product. Specific affected version information is not listed in the advisory, so all installations at risk should be considered vulnerable until a patch is applied.
Risk and Exploitability
The vulnerability carries a CVSS score of 7.8, indicating high severity. The EPSS score is below 1%, and it is not listed in the CISA KEV catalog, suggesting limited publicly known exploitation. The likely attack vector is local; an attacker with authorized access to PC Manager can exploit the missing authentication in a privileged function to elevate privileges. The risk remains significant for systems that have not applied a fix.
OpenCVE Enrichment