Microsoft Azure Portal Windows Admin Center Information Disclosure Vulnerability

Vulnerability

A vulnerability allowing external control of file names or paths has been identified in the Windows Admin Center extension for Azure Portal. This issue could enable an unauthorized attacker to gain unauthorized read-only access to the local file system.

Impact

Exploitation of this vulnerability could lead to unauthorized information disclosure, allowing access to the local file system.

Remediation

Users can apply the security update available through the Microsoft Update Catalog. For Windows Admin Center in Azure Portal, the update is included in version 0.45.0.0.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
2.5
exploitability
4.9
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.