{
  "document" : {
    "aggregate_severity" : {
      "text" : "mittel"
    },
    "category" : "csaf_base",
    "csaf_version" : "2.0",
    "distribution" : {
      "tlp" : {
        "label" : "WHITE",
        "url" : "https://www.first.org/tlp/"
      }
    },
    "lang" : "de-DE",
    "notes" : [ {
      "category" : "legal_disclaimer",
      "text" : "Das BSI ist als Anbieter für die eigenen, zur Nutzung bereitgestellten Inhalte nach den allgemeinen Gesetzen verantwortlich. Nutzerinnen und Nutzer sind jedoch dafür verantwortlich, die Verwendung und/oder die Umsetzung der mit den Inhalten bereitgestellten Informationen sorgfältig im Einzelfall zu prüfen."
    }, {
      "category" : "description",
      "text" : "Windows ist ein Betriebssystem von Microsoft.\r\nMicrosoft Windows Admin Center ist ein webbasiertes Tool zur Verwaltung von Windows Servern, Clustern und PCs.",
      "title" : "Produktbeschreibung"
    }, {
      "category" : "summary",
      "text" : "Ein Angreifer kann mehrere Schwachstellen im Microsoft Windows Backup Service, Microsoft Windows Admin Center und Microsoft Windows Remote Desktop Web Client ausnutzen, um Informationen offenzulegen und um erweiterte Rechte zu erlangen.",
      "title" : "Angriff"
    }, {
      "category" : "general",
      "text" : "- Windows",
      "title" : "Betroffene Betriebssysteme"
    } ],
    "publisher" : {
      "category" : "other",
      "contact_details" : "csaf-provider@cert-bund.de",
      "name" : "Bundesamt für Sicherheit in der Informationstechnik",
      "namespace" : "https://www.bsi.bund.de"
    },
    "references" : [ {
      "category" : "self",
      "summary" : "WID-SEC-W-2026-2401 - CSAF Version",
      "url" : "https://wid.cert-bund.de/.well-known/csaf/white/2026/wid-sec-w-2026-2401.json"
    }, {
      "category" : "self",
      "summary" : "WID-SEC-2026-2401 - Portal Version",
      "url" : "https://wid.cert-bund.de/portal/wid/securityadvisory?name=WID-SEC-2026-2401"
    }, {
      "category" : "external",
      "summary" : "Microsoft Security Advisory CVE-2026-58598 vom 2026-07-19",
      "url" : "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-58598"
    }, {
      "category" : "external",
      "summary" : "Microsoft Security Advisory CVE-2026-56171 vom 2026-07-19",
      "url" : "https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-56171"
    } ],
    "source_lang" : "en-US",
    "title" : "Microsoft Windows: Mehrere Schwachstellen",
    "tracking" : {
      "current_release_date" : "2026-07-19T22:00:00.000+00:00",
      "generator" : {
        "date" : "2026-07-20T09:07:58.242+00:00",
        "engine" : {
          "name" : "BSI-WID",
          "version" : "1.6.0"
        }
      },
      "id" : "WID-SEC-W-2026-2401",
      "initial_release_date" : "2026-07-19T22:00:00.000+00:00",
      "revision_history" : [ {
        "date" : "2026-07-19T22:00:00.000+00:00",
        "number" : "1",
        "summary" : "Initiale Fassung"
      } ],
      "status" : "final",
      "version" : "1"
    }
  },
  "product_tree" : {
    "branches" : [ {
      "branches" : [ {
        "branches" : [ {
          "category" : "product_version",
          "name" : "Remote Desktop Web Client",
          "product" : {
            "name" : "Microsoft Windows Remote Desktop Web Client",
            "product_id" : "T056771",
            "product_identification_helper" : {
              "cpe" : "cpe:/o:microsoft:windows:remote_desktop_web_client"
            }
          }
        } ],
        "category" : "product_name",
        "name" : "Windows"
      }, {
        "category" : "product_name",
        "name" : "Microsoft Windows 10",
        "product" : {
          "name" : "Microsoft Windows 10",
          "product_id" : "T056768",
          "product_identification_helper" : {
            "cpe" : "cpe:/o:microsoft:windows_10:-"
          }
        }
      }, {
        "category" : "product_name",
        "name" : "Microsoft Windows 11",
        "product" : {
          "name" : "Microsoft Windows 11",
          "product_id" : "T056769",
          "product_identification_helper" : {
            "cpe" : "cpe:/o:microsoft:windows_11:-"
          }
        }
      }, {
        "category" : "product_name",
        "name" : "Microsoft Windows Admin Center",
        "product" : {
          "name" : "Microsoft Windows Admin Center",
          "product_id" : "T056770",
          "product_identification_helper" : {
            "cpe" : "cpe:/a:microsoft:windows_admin_center:-"
          }
        }
      } ],
      "category" : "vendor",
      "name" : "Microsoft"
    } ]
  },
  "vulnerabilities" : [ {
    "cve" : "CVE-2026-56171",
    "product_status" : {
      "known_affected" : [ "T056770", "T056771" ]
    },
    "release_date" : "2026-07-19T22:00:00.000+00:00",
    "title" : "CVE-2026-56171"
  }, {
    "cve" : "CVE-2026-58598",
    "product_status" : {
      "known_affected" : [ "T056768", "T056769" ]
    },
    "release_date" : "2026-07-19T22:00:00.000+00:00",
    "title" : "CVE-2026-58598"
  } ]
}