logo

Windows Admin Center Vulnerability (CVE-2025-64669) Let Attackers Escalate Privileges

ID: 22f92436-6071-5e73-abcf-50c86940224a

STIX ID: report--22f92436-6071-5e73-abcf-50c86940224a

Feed Name: cybersecurityNews.com

Threat Score
70/100

Date Published: 2025-12-16

Date Updated: 2026-04-21

Author: Abinaya

...
...

Cymulate disclosed CVE-2025-64669, a local privilege escalation in Microsoft Windows Admin Center caused by insecure, globally writable directories under C:\ProgramData\WindowsAdminCenter. Researchers demonstrated two reliable escalation paths — abusing the extension uninstall mechanism to execute signed PowerShell scripts as NETWORK SERVICE/SYSTEM, and a TOCTOU DLL hijack against WindowsAdminCenterUpdater.exe — enabling standard local users to achieve SYSTEM privileges; Microsoft confirmed the issue, assigned an Important rating, and scheduled a patch.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.