CVE-2026-27914

7.8

Microsoft · Management Console

Improper access control in the Microsoft Management Console allows an authorized local attacker to elevate privileges on the host system.

Executive summary

A vulnerability in the Microsoft Management Console allows authenticated users to perform local privilege escalation, posing a significant risk to system integrity.

Vulnerability

This flaw is classified as improper access control (CWE-284). It enables an attacker who already possesses low-level user privileges to gain higher-level permissions locally on the target machine.

Business impact

Successful exploitation of this vulnerability allows an attacker to escalate privileges to a higher level, potentially gaining administrative control over the affected workstation or server. With a CVSS score of 7.8, this vulnerability is considered High severity, as it facilitates full system compromise, unauthorized data access, and the potential for persistent malware installation.

Remediation

Immediate Action: Update all affected Windows systems to the versions specified in the Microsoft security update guide to resolve the access control flaw.

Proactive Monitoring: Review system logs for unusual process execution patterns or unauthorized attempts to access administrative tools within the Management Console.

Compensating Controls: Restrict local user rights and implement the principle of least privilege to minimize the potential impact if a local account is compromised.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the High severity rating and the potential for full system compromise, administrators should prioritize the deployment of the relevant security updates. Ensure that all identified Windows versions are patched according to the vendor guidance to effectively mitigate the risk of local privilege escalation.

More Microsoft CVEs

Sources