Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-58643

Опубликовано: 16 июл. 2026
Источник: msrc
EPSS Низкий

Описание

Windows Admin Center Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.

FAQ

How could an attacker exploit the vulnerability?

An attacker would have to convince a user to visit a malicious website, typically via an enticement in email or instant message, or by getting them to open an email attachment.

What is the attack vector for this vulnerability?

The attack vector is address bar spoofing. A malicious website could spoof the contents of a URL bar via a specially crafted HTML page's long URL and then use it for a phishing attack.

According to the CVSS metric, user interaction is required (UI:R). What interaction would the user have to do?

This vulnerability requires that a user with an affected version of Windows access a malicious server. An attacker would have to host a specially crafted server share or website. An attacker would have no way to force users to visit this specially crafted server share or website, but would have to convince them to visit the server share or website, typically by way of an enticement in an email or chat message.

Обновления

ПродуктСтатьяОбновление
Windows Admin Center

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

EPSS

Процентиль: 15%
0.00235
Низкий

Связанные уязвимости

CVSS3: 6.1
nvd
15 дней назад

Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 6.1
github
14 дней назад

Improper neutralization of input during web page generation ('cross-site scripting') in Windows Admin Center allows an unauthorized attacker to perform spoofing over a network.

CVSS3: 6.1
fstec
18 дней назад

Уязвимость средства управления серверами Windows Admin Center, связанная с непринятием мер по защите структуры веб-страницы, позволяющая нарушителю проводить спуфинг-атаки

EPSS

Процентиль: 15%
0.00235
Низкий