Impact
The vulnerability in Windows Admin Center stems from improper authentication that enables a locally authenticated attacker to bypass normal access checks and gain higher privileges. Classified as CWE-287, the flaw involves inadequate credential verification, allowing an attacker who has any local access to assume the rights of an administrator or service account once activated.
Affected Systems
Microsoft's Windows Admin Center is the affected product. No specific version numbers are disclosed, so every deployment should be verified against the latest security update from Microsoft.
Risk and Exploitability
The CVSS score of 7.8 classifies this issue as high severity, while the EPSS score of less than 1% indicates that exploitation is currently unlikely. The vulnerability is not listed in the CISA KEV catalog. Attack requires local access to the host running Windows Admin Center; an attacker who can log in or otherwise reach the server can elevate privileges on that machine.
OpenCVE Enrichment