Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2025-26633
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Microsoft Management Console Security Feature Bypass Vulnerability
Source: NVD (National Vulnerability Database)
Vulnerability Description
Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Source: NVD (National Vulnerability Database)
Vulnerability Type
对消息或数据结构的处理不恰当
Source: NVD (National Vulnerability Database)
Vulnerability Title
Microsoft Management Console 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Microsoft Management Console是美国微软(Microsoft)公司的一个通用的管理控制台框架,用于承载和管理各种系统管理工具(称为控制台插件或管理单元)。 Microsoft Management Console存在安全漏洞。攻击者利用该漏洞可以绕过某些功能。以下产品和版本受到影响:Windows Server 2016 (Server Core installation),Windows Server 2008 for 32-bit Systems Service Pack 2
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
MicrosoftWindows 10 Version 1507 10.0.10240.0 ~ 10.0.10240.20947 -
MicrosoftWindows 10 Version 1607 10.0.14393.0 ~ 10.0.14393.7876 -
MicrosoftWindows 10 Version 1809 10.0.17763.0 ~ 10.0.17763.7009 -
MicrosoftWindows 10 Version 21H2 10.0.19044.0 ~ 10.0.19044.5608 -
MicrosoftWindows 10 Version 22H2 10.0.19045.0 ~ 10.0.19045.5608 -
MicrosoftWindows 11 version 22H2 10.0.22621.0 ~ 10.0.22621.5039 -
MicrosoftWindows 11 version 22H3 10.0.22631.0 ~ 10.0.22631.5039 -
MicrosoftWindows 11 Version 23H2 10.0.22631.0 ~ 10.0.22631.5039 -
MicrosoftWindows 11 Version 24H2 10.0.26100.0 ~ 10.0.26100.3476 -
MicrosoftWindows Server 2008 R2 Service Pack 1 6.1.7601.0 ~ 6.1.7601.27618 -
MicrosoftWindows Server 2008 R2 Service Pack 1 (Server Core installation) 6.1.7601.0 ~ 6.1.7601.27618 -
MicrosoftWindows Server 2008 Service Pack 2 6.0.6003.0 ~ 6.0.6003.23168 -
MicrosoftWindows Server 2008 Service Pack 2 (Server Core installation) 6.0.6003.0 ~ 6.0.6003.23168 -
MicrosoftWindows Server 2012 6.2.9200.0 ~ 6.2.9200.25368 -
MicrosoftWindows Server 2012 (Server Core installation) 6.2.9200.0 ~ 6.2.9200.25368 -
MicrosoftWindows Server 2012 R2 6.3.9600.0 ~ 6.3.9600.22470 -
MicrosoftWindows Server 2012 R2 (Server Core installation) 6.3.9600.0 ~ 6.3.9600.22470 -
MicrosoftWindows Server 2016 10.0.14393.0 ~ 10.0.14393.7876 -
MicrosoftWindows Server 2016 (Server Core installation) 10.0.14393.0 ~ 10.0.14393.7876 -
MicrosoftWindows Server 2019 10.0.17763.0 ~ 10.0.17763.7009 -
MicrosoftWindows Server 2019 (Server Core installation) 10.0.17763.0 ~ 10.0.17763.7009 -
MicrosoftWindows Server 2022 10.0.20348.0 ~ 10.0.20348.3328 -
MicrosoftWindows Server 2022, 23H2 Edition (Server Core installation) 10.0.25398.0 ~ 10.0.25398.1486 -
MicrosoftWindows Server 2025 10.0.26100.0 ~ 10.0.26100.3476 -
MicrosoftWindows Server 2025 (Server Core installation) 10.0.26100.0 ~ 10.0.26100.3476 -
II. Public POCs for CVE-2025-26633
#POC DescriptionSource LinkShenlong Link
1Nonehttps://github.com/sandsoncosta/CVE-2025-26633POC Details
2CVE-2025-26633 (CVSS 7.8) – Zero-day MMC .msc EvilTwin LPE actively exploited by Water Gamayun APT. PoC creates local admin via malicious MSC file on unpatched Windows 10/11/Server. Patched March 2025. Authorized testing only.https://github.com/mbanyamer/MSC-EvilTwin-Local-Privilege-EscalationPOC Details
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2025-26633
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2025-26633

No comments yet


Leave a comment