PT-2026-46132 · Unknown · Windows-Utilities-Release

CVE-2026-41858

·

Published

2026-06-04

·

Updated

2026-07-22

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions windows-utilities-release versions prior to 0.23.0
Description The Get-RandomPassword function in the randomize password job uses a predictable, clock-seeded Pseudo-Random Number Generator (PRNG), which is an algorithm for generating a sequence of numbers that approximates the properties of true randomness. This allows a network attacker to estimate the VM boot time and reconstruct a small candidate list to recover the Administrator password, bypassing the hardening control intended to secure the local Administrator account.
Recommendations Update to version 0.23.0 or later.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-41858

Affected Products

Windows-Utilities-Release