{"id":12189,"date":"2026-04-17T10:03:44","date_gmt":"2026-04-17T10:03:44","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2026\/04\/17\/one-click-rce-in-azure-windows-admin-center-allow-attacker-to-execute-arbitrary-commands\/"},"modified":"2026-04-17T10:03:44","modified_gmt":"2026-04-17T10:03:44","slug":"one-click-rce-in-azure-windows-admin-center-allow-attacker-to-execute-arbitrary-commands","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2026\/04\/17\/one-click-rce-in-azure-windows-admin-center-allow-attacker-to-execute-arbitrary-commands\/","title":{"rendered":"One-Click RCE in Azure Windows Admin Center Allow Attacker to Execute Arbitrary Commands"},"content":{"rendered":"<p>    One-Click RCE in Azure Windows Admin Center Allow Attacker to Execute Arbitrary Commands<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>Windows Admin Center is a locally deployed, browser-based management tool used by IT administrators to manage Windows servers, clients, and clusters from a centralized graphical interface.<\/p>\n<p>This newly discovered critical flaw, identified by Cymulate Research Labs, allows attackers to achieve unauthenticated, one-click remote code execution (RCE) on both Azure-integrated and on-premises WAC deployments.<\/p>\n<p>By simply coercing a victim into visiting a tampered URL, <a href=\"https:\/\/cybersecuritynews.com\/php-composer-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">adversaries can secretly execute arbitrary commands and take over target networks.<\/a><\/p>\n<p>The vulnerabilities were responsibly disclosed to Microsoft on August 22, 2025. Following the report, Microsoft successfully applied <a href=\"https:\/\/cybersecuritynews.com\/bing-ads-attack-users-with-azure-tech-support-scams\/\" target=\"_blank\" rel=\"noreferrer noopener\">server-side patches to secure all Azure-managed instances.<\/a><\/p>\n<p>Because this fix was implemented on the service side, cloud customers are protected automatically without requiring any manual action.<\/p>\n<p>However, organizations using on-premises WAC deployments must proactively update their systems to the latest release to close the vulnerability and prevent exploitation.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjBIHk34tvJ8XqQtfUOXkgAKEy_oh-HgxZ0anYSzmQKcbZRwETDQmVAWclc-o7dKCtrccm_cqxTq-mxBWxZrZqo6Mh4Z3c3inPseDLcS7pL6p_dzV3cb9b8AKyYbxcJ1YnAqZJ2XU2oNNvrrlzphrpZwsFf1uRFjI2Y2P1ia-132qoI5b-MOBi4Wr7MTAs\/s1600\/Screenshot%25202026-04-16%2520191008%2520%25281%2529.webp?ssl=1\" alt=\"The waconazure app runs in the Azure portal via an iframe(source : cymulate)\"><figcaption class=\"wp-element-caption\">The waconazure app runs in the Azure portal via an iframe (source: Cymulate)<\/figcaption><\/figure>\n<h2 class=\"wp-block-heading\" id=\"h-core-vulnerabilities-driving-the-exploit\"><strong>Core Vulnerabilities Driving the Exploit<\/strong><\/h2>\n<p>According to the technical report published by Cymulate Research Labs, the exploit chain relies on three underlying architectural weaknesses that attackers combine for maximum impact:<\/p>\n<ul class=\"wp-block-list\">\n<li>Response-based <a href=\"https:\/\/cybersecuritynews.com\/gitlab-patches-dos-xssattacks\/\" target=\"_blank\" rel=\"noreferrer noopener\">cross-site scripting (XSS) allows attackers to inject arbitrary JavaScript<\/a> into both Azure portal flows and on-premises error handling mechanisms.\n<\/li>\n<li>Insecure redirect handling causes WAC to accept externally controlled gateway URLs without proper validation, enabling threat actors to <a href=\"https:\/\/cybersecuritynews.com\/ai-sidebar-spoofing-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">hijack legitimate application flows for spoofing and phishing attacks<\/a>.\n<\/li>\n<li>Insecure credential storage in on-premises setups leaves sensitive Azure access and refresh tokens directly in the browser\u2019s local storage, exposing them to immediate theft via the XSS flaw.<\/li>\n<\/ul>\n<p>The research highlights distinct attack paths and consequences depending on how the <a href=\"https:\/\/cybersecuritynews.com\/windows-admin-center-escalation-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">Windows Admin Center environment is deployed<\/a>.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj0gbc82GvAxxBcPGLnWVd6-7NYWLB3-QNf57C-tBSClChwHxQefhG71CYA7lSk6h9FLsr_7LibRYnifUnZS88nTUxWvu2qnQPudJN27yK4nlveh2On-IXevZJE0H86Mn3qIiRA7OwF-gBlsVF9r3WxIAkdeH2fxf-qWG10e1Qd946sUE31Ua4c3iEldHo\/s1600\/Screenshot%25202026-04-16%2520181236%2520%25281%2529.webp?ssl=1\" alt=\"Unsanitized error messages enable HTML injection(source : cymulate)\"><figcaption class=\"wp-element-caption\">Unsanitized error messages enable HTML injection (source: Cymulate)<\/figcaption><\/figure>\n<ul class=\"wp-block-list\">\n<li>Azure-managed environments allow attackers to craft authentic-looking URLs containing malicious payloads that prompt fake basic or NTLM authentication, silently harvesting user credentials from a trusted Microsoft origin.\n<\/li>\n<li>On-premises deployments carry a significantly higher security impact because threat actors can force the gateway to execute arbitrary PowerShell commands on managed servers.\n<\/li>\n<li>Connected l<a href=\"https:\/\/cybersecuritynews.com\/azure-identity-token-vulnerability\/\" target=\"_blank\" rel=\"noreferrer noopener\">ocal gateways expose stored Azure tokens<\/a>, facilitating lateral movement that grants attackers the victim\u2019s full cloud privileges and tenant control.<\/li>\n<\/ul>\n<h2 class=\"wp-block-heading\" id=\"h-the-exploit-chain-in-action\"><strong>The Exploit Chain in Action<\/strong><\/h2>\n<p><a href=\"https:\/\/cymulate.com\/blog\/cve-2026-32196-one-click-rce-windows-admin-center\/\" id=\"https:\/\/cymulate.com\/blog\/cve-2026-32196-one-click-rce-windows-admin-center\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Cymulate researchers demonstrated that the complete attack chain<\/a> requires minimal user interaction.<\/p>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEgWYVbaXJys8VvcN-CfxF1hyphenhyphen4rNVCqEWqLtLZ_p1UOR8hKY2HapbaWpQul2ims1OWtTpxI4RNJTU-vqa3VfOey0XoEZTqzNGUnhSwH0dtBwVq2AZk-YHm_ua5E8CQBNOLhxng1-F9zgwX33JzOIp5RM3ibtCj9D4GwF0NUU8f2A7CILu3wlzW0UMF8D9mM\/s1600\/Screenshot%25202026-04-16%2520190907%2520%25281%2529.webp?ssl=1\" alt=\"\"><\/figure>\n<figure class=\"wp-block-image size-large\"><img data-recalc-dims=\"1\" decoding=\"async\" src=\"https:\/\/i0.wp.com\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEj9e-h2ZvN-koaPxtr5s2O4f13jqVGsRUYCLynG9AFkIYpOg2_1LPfD_aFyPBV3jreuCP9C6OSxh4YCxJsSE5zCVPSLxwesj0Vuhrp-9ZkvKVGFUgyMjseSTnLKayaDeAhFtCTZ_K7CoItYEoeoQvAZYlZ9h-6tzHQaQ-0zGpTEqarBqZXfrIkNl8yfGuc\/s1600\/Screenshot%25202026-04-16%2520190923%2520%25281%2529.webp?ssl=1\" alt=\"An attacker-hosted payload can automatically steal client credentials( source : cymulate)\"><figcaption class=\"wp-element-caption\">An attacker-hosted payload can automatically steal client credentials (Source: Cymulate)<\/figcaption><\/figure>\n<p>An adversary needs to register a valid domain name, secure a trusted web certificate, and forge a WAC gateway URL. This malicious link can then be <a href=\"https:\/\/cybersecuritynews.com\/fraud-as-a-service\/\" target=\"_blank\" rel=\"noreferrer noopener\">delivered through phishing emails, masked links, or automated web redirection<\/a>.<\/p>\n<p>Once the unsuspecting victim clicks the link, the WAC application automatically redirects traffic to the attacker-controlled server. The rogue server then responds with a crafted error message containing hidden scripts.<\/p>\n<p>Because the application fails to sanitize the incoming response properly, the malicious code executes directly within the highly privileged WAC browser environment.<\/p>\n<p>This exploit clearly proves that developers must rigorously validate both client input and server responses to prevent complex attacks. While Azure-hosted WAC customers are already protected, the security risk remains critical for internal networks.<\/p>\n<p>Cymulate Research Labs strongly advises all security teams managing on-premises Windows Admin Center deployments to upgrade to the latest, patched Microsoft release immediately.<\/p>\n<p>Administrators must verify that no outdated instances remain active on their network to prevent complete infrastructure compromise.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 94%,rgb(169,184,195) 100%)\"><strong>Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>, <a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>, and <a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">X<\/a> for daily cybersecurity updates. <a href=\"https:\/\/cybersecuritynews.com\/contact-us\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Contact us<\/a> to feature your stories.<\/strong><\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/azure-windows-admin-center-rce\/\">One-Click RCE in Azure Windows Admin Center Allow Attacker to Execute Arbitrary Commands<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Abinaya<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/azure-windows-admin-center-rce\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>One-Click RCE in Azure Windows Admin Center Allow Attacker to Execute Arbitrary Commands Windows Admin Center is a locally deployed, browser-based management tool used by IT administrators to manage Windows servers, clients, and clusters from a centralized graphical interface. This newly discovered critical flaw, identified by Cymulate Research Labs, allows attackers to achieve unauthenticated, one-click [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[129,63,648,395],"tags":[130],"class_list":["post-12189","post","type-post","status-publish","format-standard","hentry","category-cyber-security","category-cyber-security-news","category-vulnerability-news","category-windows","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12189"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=12189"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/12189\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=12189"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=12189"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=12189"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}