QID 92031

Date Published: 2023-07-12

QID 92031: Windows Admin Center Spoofing Vulnerability - July 2023

Windows Admin Center is a customer-deployed, browser-based app for managing servers, clusters, hyper-converged infrastructure, and Windows 10 PCs.

Windows Admin Center is prone to Spoofing Vulnerability.
Affected Products:
Windows Admin Center version prior to 1.5.2306.14001

QID Detection Logic (authenticated):
Windows: Checks for installed vulnerable version either from SmeDesktop.exe or sme.exe

Successful exploitation of this vulnerability may affect Integrity and Availability.

  • CVSS V3 rated as High - 6.8 severity.
  • CVSS V2 rated as Medium - 5.5 severity.
  • Solution
    Customers are advised to refer Windows Admin Center Security Advisory for more information.
    Vendor References

    CVEs related to QID 92031

    Software Advisories
    Advisory ID Software Component Link
    Windows Admin Center Security Advisory URL Logo msrc.microsoft.com/update-guide/vulnerability/CVE-2023-29347