PT-2026-46132 · Unknown · Windows-Utilities-Release
CVE-2026-41858
·
Published
2026-06-04
·
Updated
2026-07-22
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
windows-utilities-release versions prior to 0.23.0
Description
The
Get-RandomPassword function in the randomize password job uses a predictable, clock-seeded Pseudo-Random Number Generator (PRNG), which is an algorithm for generating a sequence of numbers that approximates the properties of true randomness. This allows a network attacker to estimate the VM boot time and reconstruct a small candidate list to recover the Administrator password, bypassing the hardening control intended to secure the local Administrator account.Recommendations
Update to version 0.23.0 or later.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows-Utilities-Release