Microsoft Management Console是美国微软(Microsoft)公司的一个通用的管理控制台框架,用于承载和管理各种系统管理工具(称为控制台插件或管理单元)。 Microsoft Management Console存在安全漏洞。攻击者利用该漏洞可以绕过某些功能。以下产品和版本受到影响:Windows Server 2016 (Server Core installation),Windows Server 2008 for 32-bit Systems Service Pack 2
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | None | https://github.com/sandsoncosta/CVE-2025-26633 | POC Details |
| 2 | CVE-2025-26633 (CVSS 7.8) – Zero-day MMC .msc EvilTwin LPE actively exploited by Water Gamayun APT. PoC creates local admin via malicious MSC file on unpatched Windows 10/11/Server. Patched March 2025. Authorized testing only. | https://github.com/mbanyamer/MSC-EvilTwin-Local-Privilege-Escalation | POC Details |
No public POC found.
Login to generate AI POC| CVE-2025-26645 | 8.8 HIGH | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2025-24056 | 8.8 HIGH | Windows Telephony Service Remote Code Execution Vulnerability |
| CVE-2025-24051 | 8.8 HIGH | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability |
| CVE-2025-24049 | 8.4 HIGH | Azure Command Line Integration (CLI) Elevation of Privilege Vulnerability |
| CVE-2025-24084 | 8.4 HIGH | Windows Subsystem for Linux (WSL2) Kernel Remote Code Execution Vulnerability |
| CVE-2025-24064 | 8.1 HIGH | Windows Domain Name Service Remote Code Execution Vulnerability |
| CVE-2025-24045 | 8.1 HIGH | Windows Remote Desktop Services Remote Code Execution Vulnerability |
| CVE-2025-24035 | 8.1 HIGH | Windows Remote Desktop Services Remote Code Execution Vulnerability |
| CVE-2025-24050 | 7.8 HIGH | Windows Hyper-V Elevation of Privilege Vulnerability |
| CVE-2025-24077 | 7.8 HIGH | Microsoft Word Remote Code Execution Vulnerability |
| CVE-2025-24985 | 7.8 HIGH | Windows Fast FAT File System Driver Remote Code Execution Vulnerability |
| CVE-2025-24057 | 7.8 HIGH | Microsoft Office Remote Code Execution Vulnerability |
| CVE-2025-24061 | 7.8 HIGH | Windows Mark of the Web Security Feature Bypass Vulnerability |
| CVE-2025-24059 | 7.8 HIGH | Windows Common Log File System Driver Elevation of Privilege Vulnerability |
| CVE-2025-24046 | 7.8 HIGH | Kernel Streaming Service Driver Elevation of Privilege Vulnerability |
| CVE-2025-24066 | 7.8 HIGH | Kernel Streaming Service Driver Elevation of Privilege Vulnerability |
| CVE-2025-24067 | 7.8 HIGH | Kernel Streaming Service Driver Elevation of Privilege Vulnerability |
| CVE-2025-24072 | 7.8 HIGH | Microsoft Local Security Authority (LSA) Server Elevation of Privilege Vulnerability |
| CVE-2025-24075 | 7.8 HIGH | Microsoft Excel Remote Code Execution Vulnerability |
| CVE-2025-24048 | 7.8 HIGH | Windows Hyper-V Elevation of Privilege Vulnerability |
Showing top 20 of 57 CVEs. View all on vendor page → →
No comments yet