Impact
Missing authentication for a critical function in Windows Modern Device Management (MDM) permits an authorized local attacker to bypass a security feature. The vulnerability enables a user who has already authenticated to exploit a privileged MDM function, potentially allowing them to alter or remove device management policies or other configuration settings. This escalation of privilege could lead to tampering with device security controls, thereby compromising device integrity and potentially the confidentiality of data stored on or transmitted by the device.
Affected Systems
Microsoft Windows 10 versions 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; Windows Server 2019 (both full and Server Core), Windows Server 2022, and Windows Server 2025 (both full and Server Core).
Risk and Exploitability
The CVSS score of 5.5 indicates a moderate severity. EPSS is not available, so the likelihood of exploitation in the wild remains uncertain. The vulnerability is not listed in CISA KEV. Attackers would need local access and an authenticated user account to exploit the flaw, suggesting a local, authorized attack vector. Successful exploitation could enable the attacker to bypass security controls and potentially elevate privileges on the affected device.
OpenCVE Enrichment