HIGH

CVE-2025-26633

Microsoft Windows 10 1507 2025-03-11 CVSS v3.1
CVSS
7
KEV

Description

Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.

Summary dbcve.org

Improper input neutralization in Microsoft Management Console enables a local unauthorized attacker to bypass a security feature. The vulnerability stems from insufficient validation or sanitization of input within MMC, allowing security controls to be circumvented through the console interface.

Mitigation

Apply Microsoft security updates for CVE-2025-26633 when available. Until patch deployment, limit local administrative access and monitor for suspicious MMC usage patterns.

Proof of Concept

Weakness (CWE)

CWE-707

EPSS Score

30.39%
Probability of exploitation in next 30 days
98.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE