Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally
Description
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally
Remediation
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: Microsoft
PRODUCT: Windows Admin Center
AFFECTED_VERSIONS: See vendor advisory for specific affected versions
---END_METADATA---
Description Summary:
Improper authentication within Microsoft Windows Admin Center enables an authorized attacker to escalate privileges via network access. This flaw facilitates unauthorized administrative control.
Executive Summary:
A privilege escalation vulnerability in Microsoft Windows Admin Center allows authenticated attackers to elevate their permissions across a network, potentially compromising managed infrastructure.
Vulnerability Details
CVE-ID: CVE-2026-26119
Affected Software: Microsoft Windows Admin Center
Affected Versions: See vendor advisory for specific affected versions
Vulnerability: This vulnerability stems from improper authentication handling within the Windows Admin Center interface. An attacker who has already obtained authorized access to the network can exploit this flaw to elevate their privileges to a higher level than intended.
Business Impact
A successful exploit of this vulnerability could allow a low-privileged user to gain administrative rights over the Windows Admin Center, leading to full control over connected servers and infrastructure. With a CVSS score of 8.8, the risk is classified as High, as it directly threatens the integrity of the management plane and could result in widespread system downtime or unauthorized configuration changes.
Remediation Plan
Immediate Action: Apply the latest security updates provided by Microsoft for Windows Admin Center immediately to resolve the authentication logic error.
Proactive Monitoring: Review Windows Admin Center access logs for unusual login patterns or privilege changes and monitor network traffic for suspicious activity targeting management ports.
Compensating Controls: Restrict access to the Windows Admin Center interface using network-level access control lists (ACLs) or a VPN to ensure only trusted internal devices can reach the service.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of February 18, 2026, there is no public information indicating active exploitation of this vulnerability. However, due to the nature of the flaw and its location in a central management tool, the potential for targeted exploitation is high.
Analyst Recommendation
The high CVSS score of 8.8 underscores the critical nature of this privilege escalation flaw. Because Windows Admin Center is a gateway to broader server infrastructure, administrators must prioritize the application of the vendor-supplied patch. Immediate remediation is essential to prevent internal lateral movement and unauthorized administrative takeovers.