AI description
Automated description summarized from trusted sources.
CVE-2026-58631 is identified as a Remote Code Execution (RCE) vulnerability affecting Windows Admin Center (WAC). This flaw was disclosed as part of Microsoft's July 2026 Patch Tuesday updates. The vulnerability allows an attacker to execute arbitrary code remotely within the context of the Windows Admin Center.
- Description
- Improper authorization in Windows Admin Center allows an authorized attacker to execute code locally.
- Source
- secure@microsoft.com
- NVD status
- Analyzed
- Products
- windows_admin_center
CVSS 3.1
- Type
- Secondary
- Base score
- 7.8
- Impact score
- 5.9
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Severity
- HIGH
- secure@microsoft.com
- CWE-285
- Hype score
- Not currently trending
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:microsoft:windows_admin_center:*:*:*:*:*:*:*:*",
"matchCriteriaId": "6B676562-D90E-4904-B4A6-4DA8C7A58C2D",
"versionEndExcluding": "2606",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]