Windows Admin Center Vulnerability (CVE-2025-64669) Let Attackers Escalate Privileges
ID: 22f92436-6071-5e73-abcf-50c86940224a
STIX ID: report--22f92436-6071-5e73-abcf-50c86940224a
Feed Name: cybersecurityNews.com
Cymulate disclosed CVE-2025-64669, a local privilege escalation in Microsoft Windows Admin Center caused by insecure, globally writable directories under C:\ProgramData\WindowsAdminCenter. Researchers demonstrated two reliable escalation paths — abusing the extension uninstall mechanism to execute signed PowerShell scripts as NETWORK SERVICE/SYSTEM, and a TOCTOU DLL hijack against WindowsAdminCenterUpdater.exe — enabling standard local users to achieve SYSTEM privileges; Microsoft confirmed the issue, assigned an Important rating, and scheduled a patch.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
