Rahul Bhor, Sr. Security Engineer, Coupa Software

Ramesh Donthagani, Lead Security Engineer, Coupa Software


Rahul Bhor: Passionate Learner for OffSec and Security Engineering. Working collaboratively with Security Architecture, Security Engineering and Threat Management @ Coupa Software 


Ramesh Donthagani: With 17+ years of experience in IT, specialized in application security, and a strong background in Microsoft technologies such as .NET, C#, and SharePoint. Over the past 7 years, focused on DAST, SAST, SCA, Vulnerability Assessment, and Penetration Testing, helping organizations secure their applications and digital ecosystems. Holds recognized certifications including eWPTXv2, AWS Certified Security – Specialty, and CEH. 

talks & Q&A

The Master Key Nobody’s Watching: Hacking Your Way from Help Desk to Hybrid Datacenter


Description

Windows Admin Center sits at the heart of modern hybrid infrastructure – a single browser tab controlling every server, cluster, virtual machine, and Azure resource in your environment. It runs with the highest privileges on the network. It bridges on-premise and cloud. And until recently, it was wide open to anyone with a help desk login.


Between late 2025 and early 2026, three critical vulnerabilities turned WAC from a management convenience into an attacker's dream. CVE-2025-64669, discovered by Cymulate, revealed that WAC's installation directory was writable by standard users – allowing any local account to hijack DLLs and escalate straight to SYSTEM. CVE-2026-26119, found by Semperis (CVSS 8.8), exposed broken authentication in WAC's REST API, enabling low-privilege users to impersonate administrators across the network with crafted requests. CVE-2026-23660 extended the same flaw into Azure, where WAC operates as a VM extension - turning an on-premise compromise into a cloud pivot.


Chain all three, and the attack path is devastatingly simple: help desk credentials to local SYSTEM, SYSTEM to network-wide admin, network admin to Azure. Full hybrid datacenter ownership – no additional exploits required.


This talk walks through the complete exploitation chain live, then pivots to defense. We dissect the telemetry each attack step generates and deliver immediately deployable detection: KQL queries for Sentinel and Defender for Endpoint, behavioral alert configurations for SOC teams, and a hardening checklist covering network segmentation, just-in-time access, MFA enforcement, and directory permission lockdown. You'll see exactly how the attack works – and leave with everything you need to ensure it doesn't work against you.