HIGH
CVE-2025-26633
CVSS
7
KEV
Description
Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.
Summary dbcve.org
Improper input neutralization in Microsoft Management Console enables a local unauthorized attacker to bypass a security feature. The vulnerability stems from insufficient validation or sanitization of input within MMC, allowing security controls to be circumvented through the console interface.
Mitigation
Apply Microsoft security updates for CVE-2025-26633 when available. Until patch deployment, limit local administrative access and monitor for suspicious MMC usage patterns.
Weakness (CWE)
CWE-707
EPSS Score
30.39%
Probability of exploitation in next 30 days
98.1th percentile
References
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26633
Vendor Advisory
https://www.vicarius.io/vsociety/posts/cve-2025-26633-security-feature-bypass-in-microsoft-management-console-detection-script
Exploit, Third Party Advisory
https://www.vicarius.io/vsociety/posts/cve-2025-26633-security-feature-bypass-in-microsoft-management-console-mitigation-script
Exploit, Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-26633
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.