Microsoft Windows Admin Center Privilege Escalation Vulnerability

Vulnerability

A vulnerability in Windows Admin Center allows an authorized attacker to elevate privileges over a network. This issue arises from improper access control, enabling low-privileged users to send specially crafted requests to the Windows Admin Center update API and perform actions beyond their assigned permissions.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing attackers to gain elevated rights and access within the affected system or application.

Remediation

Users are advised to download the security update for Windows Admin Center in Azure Portal. Instructions are available in the Windows Admin Center Release Notes.

Added: May 12, 2026, 7:24 PM
Updated: May 12, 2026, 7:24 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
5.0
exploitability
4.9
remediation
7.7
relevance
7.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.