PT-2026-2761 · Microsoft · Windows Admin Center
Ben Zamir
+2
·
Published
2026-01-13
·
Updated
2026-05-12
·
CVE-2026-20965
CVSS v3.1
7.5
High
| Vector | AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Windows Admin Center versions prior to 0.70.00
Description
Improper verification of cryptographic signatures in the Azure AD SSO implementation of Windows Admin Center allows an authorized attacker with local administrator access on a machine to bypass authentication and authorization mechanisms. The issue stems from the improper validation of Proof-of-Possession (PoP) tokens, where a stolen admin access token can be mixed with a forged PoP token to impersonate privileged users. This can lead to local privilege escalation, lateral movement across the entire tenant, and tenant-wide remote code execution (RCE). The exploitation involves sending a specially crafted HTTPS request.
Recommendations
Update Windows Admin Center Azure Extension to version 0.70.00 or later.
Fix
RCE
Improper Verification of Cryptographic Signature
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows Admin Center