Impact
Improper authorization in Microsoft Windows Admin Center allows an authorized attacker to execute code locally on the device. The flaw is classified as CWE‑285 and permits running arbitrary code with the privileges of the authenticated session.
Affected Systems
The vulnerability applies to Microsoft Windows Admin Center. All deployments of Windows Admin Center that have not applied the latest security update may be affected; no specific version range is provided.
Risk and Exploitability
The CVSS score of 7.8 indicates a high‑severity vulnerability, while the EPSS score is less than 1 % and the issue is not listed in CISA’s KEV catalog. Exploitation requires an attacker to have authenticated access to the WAC portal; the missing authorization enables the attacker to execute arbitrary code locally on the target machine. Because the attack vector depends on existing privileges, widespread exploitation is limited to environments where administrators have not been restricted from the portal.
OpenCVE Enrichment