PT-2025-10848 · Microsoft · Management Console+1

Aliakbar Zahravi

·

Published

2025-03-11

·

Updated

2026-02-06

·

CVE-2025-26633

CVSS v3.1

7.0

High

VectorAV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Microsoft Windows versions prior to the patch released in March 2025.
Description A security feature bypass vulnerability exists in Microsoft Management Console (MMC). This vulnerability, also known as MSC EvilTwin (CVE-2025-26633), allows an unauthorized attacker to bypass security features locally. The vulnerability is actively exploited by multiple threat actors, including the Russian-aligned groups Water Gamayun (also known as EncryptHub and LARVA-208) and others. Attackers are leveraging this vulnerability through various methods, including social engineering via Microsoft Teams, malicious websites redirecting to compromised sites, and the use of rogue .msc files disguised as legitimate applications. Exploitation involves techniques like abusing the TaskPad snap-in, executing PowerShell commands, and utilizing custom malware such as SilentPrism, DarkWisp, and Fickle Stealer. The attacks involve the exploitation of a zero-day vulnerability and the use of signed .msi files to deliver malicious payloads. The exploitation of this vulnerability can lead to data breaches, unauthorized access, and the deployment of backdoors. Several reports indicate that this vulnerability is being used to steal data, credentials, and cryptocurrency wallets.
Recommendations Apply the latest security updates from Microsoft released in March 2025 to patch CVE-2025-26633. Restrict access to the Management Console. Monitor systems for exploitation attempts. As a temporary workaround, consider disabling or restricting the use of the mmc.exe application.

Exploit

Fix

LPE

RCE

Improper Neutralization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2025-02567
BDU:2025-05428
CVE-2025-26633
ZDI-25-150

Affected Products

Management Console
Windows