Back to search
CVE-2026-1680
Published: Jan 30, 2026
Modified: Feb 2, 2026
PUBLISHED
Description
Improper access control in the WCF endpoint in Edgemo (now owned by Danoffice IT) Local Admin Service 1.2.7.23180 on Windows allows a local user to escalate their privileges to local administrator via direct communication with the LocalAdminService.exe named pipe, bypassing client-side group membership restrictions.
| Vendor | Product | Versions |
|---|---|---|
Edgemo (Danoffice IT) | Local Admin Service | affected 1.2.7.23180 |
Weaknesses (CWE)
References
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now