CVE-2026-1680

Improper access control in the WCF endpoint in Edgemo (now owned by Danoffice IT) Local Admin Service 1.2.7.23180 on Windows allows a local user to escalate their privileges to local administrator via direct communication with the LocalAdminService.exe named pipe, bypassing client-side group membership restrictions.
CVSS

No CVSS.

Configurations

No configuration.

History

02 Feb 2026, 17:16

Type Values Removed Values Added
Summary
  • (es) Control de acceso inadecuado en el endpoint WCF en Edgemo (ahora propiedad de Danoffice IT) Servicio de Administrador Local 1.2.7.23180 en Windows permite a un usuario local escalar sus privilegios a administrador local mediante comunicación directa con la tubería con nombre LocalAdminService.exe, eludiendo las restricciones de membresía de grupo del lado del cliente.
References () https://retest.dk/local-privilege-escalation-vulnerability-found-in-local-admin-service/ - () https://retest.dk/local-privilege-escalation-vulnerability-found-in-local-admin-service/ -

30 Jan 2026, 07:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-30 07:16

Updated : 2026-02-04 16:34


NVD link : CVE-2026-1680

Mitre link : CVE-2026-1680

CVE.ORG link : CVE-2026-1680


JSON object : View

Products Affected

No product.

CWE
CWE-250

Execution with Unnecessary Privileges