CVE-2026-20965
Microsoft · Published January 13, 2026
7.5
CVSS v3.1
HIGHPatch availableGet patch
Description
Windows Admin Center Elevation of Privilege Vulnerability. Improper verification of cryptographic signature in Windows Admin Center allows an authorized attacker to elevate privileges locally.
Affected Products
- Windows Admin Center in Azure Portal
CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H/E:U/RL:O/RC:C