PT-2026-20332 · Microsoft · Windows Admin Center
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Windows Admin Center versions prior to 2511
Description
Improper authentication in Windows Admin Center allows an authorized attacker to elevate privileges over a network. An authenticated low-privileged user can gain the rights of the account running the Windows Admin Center service. Because Windows Admin Center serves as a centralized control plane for managing servers, clusters, and Active Directory-joined systems, this flaw could potentially lead to full domain compromise under certain conditions.
Recommendations
Update Windows Admin Center to version 2511.
Fix
LPE
Improper Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows Admin Center