CVE-2026-1680

Improper access control in the WCF endpoint in Edgemo (now owned by Danoffice IT) Local Admin Service 1.2.7.23180 on Windows allows a local user to escalate their privileges to local administrator via direct communication with the LocalAdminService.exe named pipe, bypassing client-side group membership restrictions.
Configurations

Configuration 1 (hide)

cpe:2.3:a:danofficeit:local_admin_service:1.2.7.23180:*:*:*:*:windows:*:*

History

03 Mar 2026, 15:06

Type Values Removed Values Added
References () https://retest.dk/local-privilege-escalation-vulnerability-found-in-local-admin-service/ - () https://retest.dk/local-privilege-escalation-vulnerability-found-in-local-admin-service/ - Exploit, Third Party Advisory
References () https://www.danofficeit.com/howwedoit/workplace/management/ - () https://www.danofficeit.com/howwedoit/workplace/management/ - Product
CPE cpe:2.3:a:danofficeit:local_admin_service:1.2.7.23180:*:*:*:*:windows:*:*
First Time Danofficeit
Danofficeit local Admin Service
CWE NVD-CWE-Other
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8

02 Feb 2026, 17:16

Type Values Removed Values Added
Summary
  • (es) Control de acceso inadecuado en el endpoint WCF en Edgemo (ahora propiedad de Danoffice IT) Servicio de Administrador Local 1.2.7.23180 en Windows permite a un usuario local escalar sus privilegios a administrador local mediante comunicación directa con la tubería con nombre LocalAdminService.exe, eludiendo las restricciones de membresía de grupo del lado del cliente.
References () https://retest.dk/local-privilege-escalation-vulnerability-found-in-local-admin-service/ - () https://retest.dk/local-privilege-escalation-vulnerability-found-in-local-admin-service/ -

30 Jan 2026, 07:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-30 07:16

Updated : 2026-03-03 15:06


NVD link : CVE-2026-1680

Mitre link : CVE-2026-1680

CVE.ORG link : CVE-2026-1680


JSON object : View

Products Affected

danofficeit

  • local_admin_service
CWE
CWE-250

Execution with Unnecessary Privileges

NVD-CWE-Other