Windows Admin Center Vulnerability (CVE-2025-64669) Let Attackers Escalate Privileges
A local privilege escalation vulnerability has been identified in Microsoft's Windows Admin Center (WAC), affecting versions up to 2.4.2.1, including environments running WAC 2411 and earlier. The vulnerability is tracked as CVE-2025-64669.
A local privilege escalation vulnerability has been identified in Microsoft's Windows Admin Center (WAC), affecting versions up to 2.4.2.1, including environments running WAC 2411 and earlier. The vulnerability is tracked as CVE-2025-64669.
The flaw is due to insecure directory permissions on the folder C:\ProgramData\WindowsAdminCenter . This directory is writable by standard users and used by services running with elevated privileges. As Windows Admin Center is widely utilized for managing Windows Server, clusters, hyper-converged infrastructure, and Windows 10/11 endpoints, this issue presents a significant risk across technology layers.
The vulnerability allows standard users with local filesystem access on WAC hosts to potentially escalate privileges. Researchers identified that the writable directory hosts components and processes operating under NETWORK SERVICE and SYSTEM privileges, which can compromise Windows security boundaries.
Analysis revealed two exploitation chains allowing low-privileged users to gain SYSTEM-level access:
The flaw is due to insecure directory permissions on the folder C:\ProgramData\WindowsAdminCenter .
Extension Uninstall Mechanism: By exploiting the extension uninstall process, an attacker can execute PowerShell scripts with elevated privileges. Updater DLL Loading Flaw: A race condition in the updater component allows loading malicious DLLs with SYSTEM privileges.
Microsoft has confirmed the vulnerability and assigned it an Important severity rating. Cymulate has integrated a scenario into its Exposure Validation platform to help organizations assess and validate their exposure to this vulnerability.
Microsoft plans to release a fix in the December 10, 2025 Patch Tuesday update. Organizations are advised to monitor and apply the corresponding updates promptly to mitigate potential risks.
For further information and updates, organizations can refer to Microsoft's official security advisory .
Based on reporting by Cyber Security News.
