Azure Identity Token Vulnerability Enables Tenant-Wide Compromise in Windows Admin Center
ID: f01918ba-2e59-5c27-812b-24aa3100206a
STIX ID: report--f01918ba-2e59-5c27-812b-24aa3100206a
Feed Name: cybersecurityNews.com
A high-severity flaw (CVE-2026-20965) in Windows Admin Center's Azure Single Sign-On allows attackers with local admin on a WAC-enabled VM/Arc machine and a privileged Azure Portal connection to mix tokens (stolen WAC.CheckAccess + forged PoP) to perform tenant-wide RCE, lateral movement, and cross-subscription compromise; Microsoft patched it in Windows Admin Center Azure Extension v0.70.00 on 2026-01-13 and operators should apply the update, restrict JIT/NSG to gateway-only, and monitor for anomalous WAC accounts and InvokeCommand activity.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
