Description
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally.
Published: 2026-07-14
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Windows Admin Center stems from improper authentication that enables a locally authenticated attacker to bypass normal access checks and gain higher privileges. Classified as CWE-287, the flaw involves inadequate credential verification, allowing an attacker who has any local access to assume the rights of an administrator or service account once activated.

Affected Systems

Microsoft's Windows Admin Center is the affected product. No specific version numbers are disclosed, so every deployment should be verified against the latest security update from Microsoft.

Risk and Exploitability

The CVSS score of 7.8 classifies this issue as high severity, while the EPSS score of less than 1% indicates that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Attack requires local access to the host running Windows Admin Center; an attacker who can log in or otherwise reach the server can elevate privileges on that machine.

Generated by OpenCVE AI on July 31, 2026 at 09:13 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Microsoft security update for Windows Admin Center released in the latest update guide.
  • Enable stricter authentication for Windows Admin Center, such as multi‑factor authentication or managed identities, to limit remote or local access to trusted administrators.
  • Restrict the set of local administrators allowed to use Windows Admin Center and audit privileged access logs for unusual activity.
  • Configure role‑based access controls within Windows Admin Center to restrict use of high‑privilege functions and monitor all access attempts.

Generated by OpenCVE AI on July 31, 2026 at 09:13 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 15 Jul 2026 11:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges locally.
Title Windows Admin Center Elevation of Privilege Vulnerability
First Time appeared Microsoft
Microsoft windows Admin Center
Weaknesses CWE-287
CPEs cpe:2.3:a:microsoft:windows_admin_center:*:*:*:*:*:*:*:*
Vendors & Products Microsoft
Microsoft windows Admin Center
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C'}


Subscriptions

Microsoft Windows Admin Center
cve-icon MITRE

Status: PUBLISHED

Assigner: microsoft

Published:

Updated: 2026-08-03T22:53:36.568Z

Reserved: 2026-06-23T18:29:51.054Z

Link: CVE-2026-57107

cve-icon Vulnrichment

Updated: 2026-07-15T10:26:21.536Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T09:15:06Z

Weaknesses