CVE-2026-42834

7.8

Microsoft · Windows Admin Center

An improper link resolution vulnerability in Microsoft Windows Admin Center allows an authenticated local attacker to perform privilege escalation.

Executive summary

A local privilege escalation vulnerability in Microsoft Windows Admin Center could allow an authorized attacker to gain elevated system privileges.

Vulnerability

This flaw involves improper link resolution before file access (CWE-59), which can be exploited by an attacker with local, low-privileged access to manipulate file paths and elevate privileges.

Business impact

Successful exploitation allows a local user to bypass security controls and gain escalated privileges, potentially leading to a full system compromise. With a CVSS score of 7.8, this vulnerability represents a significant risk to internal server integrity and administrative control, necessitating prompt patching to prevent unauthorized lateral movement or host takeover.

Remediation

Immediate Action: Update Microsoft Windows Admin Center to version 0.72.0.0 or later as provided in the official Microsoft security update.

Proactive Monitoring: Audit local system logs for unusual file access patterns or unexpected process execution originating from low-privileged service accounts.

Compensating Controls: Ensure that administrative access to the server hosting Windows Admin Center is strictly restricted to authorized personnel, minimizing the pool of users capable of local exploitation.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the potential for local privilege escalation, organizations should prioritize updating Windows Admin Center to the patched version. While the requirement for local access limits the immediate scope, the risk of total system compromise warrants rapid deployment of the vendor-supplied security update to maintain a secure administrative environment.

More Microsoft CVEs