Impact
The Windows Admin Center contains an improper neutralization of input during web page generation that qualifies as a cross‑site scripting flaw. This weakness allows an unauthorized user to inject specially crafted content into a page that the service renders. The injected payload can make the application display a page that appears to originate from a trusted administrator, effectively spoofing a legitimate user. If successful, the attacker can masquerade as that user over the network, potentially gaining access to administrative functions or confidential information.
Affected Systems
All installations of Microsoft Windows Admin Center that have not applied the latest updates are susceptible. The affected software is the Windows Admin Center product; any deployment exposing the web portal to external or internal networks carries risk if not patched.
Risk and Exploitability
The CVSS score of 6.1 indicates moderate severity. An EPSS score of less than 1 % suggests a low likelihood that this vulnerability will be widely exploited in the short term. The vulnerability is not present in the CISA KEV catalog. Exploitation requires an attacker to acquire a web session that can reach the Admin Center portal, then supply malicious input to a page‑generation component. Based on the description, it is inferred that the attack vector is remote, through the web interface, and is mitigated by limiting network access and applying the vendor patch.
OpenCVE Enrichment