Impact
An authentication flaw in Windows Admin Center permits an attacker who already has authorized access to read sensitive configuration or system information over the network, effectively compromising confidentiality. The flaw arises from improper validation of user credentials or session tokens, enabling the disclosure of data that should be protected. This vulnerability is classified as CWE-287 (Authentication Bypass) and CWE-94 (Improper Control of Generation of Code).
Affected Systems
Microsoft Windows Admin Center is the affected product. The vulnerability applies to all installations where the authentication mechanism has not been updated to the latest patch. No specific version range is documented in the advisory, so all current releases should be considered vulnerable until a patch is applied.
Risk and Exploitability
With a CVSS score of 6.5, the vulnerability presents moderate risk; however, its EPSS score of less than 1% suggests that exploitation attempts are unlikely at present. The vulnerability is not listed in CISA's KEV catalog, indicating that no widespread exploits are known. The attack vector is network-based and requires the attacker to already have authorized access to the Windows Admin Center instance.
OpenCVE Enrichment