Impact
Windows Admin Center allows an attacker who is already granted network access to bypass authentication controls and gain elevated privileges on the target system. The vulnerability is a flaw in authentication handling that enables privilege escalation, potentially allowing the attacker to perform any action that higher‑level users can, thereby compromising confidentiality, integrity, and availability of the managed infrastructure.
Affected Systems
The affected product is Microsoft Windows Admin Center. Version information is not specified in the available data, so any installation of this product is potentially vulnerable unless proven otherwise.
Risk and Exploitability
The CVSS score of 8.1 indicates high severity. The EPSS score is below 1% and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is over the network, requiring the attacker to connect to the Admin Center from a client that has network access. No known public exploit is documented, but given the high CVSS score and the network path, entities should treat this as a serious risk.
OpenCVE Enrichment