CVE-2025-26633 — Microsoft Management Console Security Feature Bypass Vulnerability
Executive Summary
Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.
Overview
CVSS Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
EPSS Score
Affected Products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows 10 for 32-bit Systems | 5053618 (Security Update) |
Important | Security Feature Bypass | Yes |
| Windows 10 for x64-based Systems | 5053618 (Security Update) |
Important | Security Feature Bypass | Yes |
| Windows 10 Version 1607 for 32-bit Systems | 5053594 (Security Update) |
Important | Security Feature Bypass | Yes |
| Windows 10 Version 1607 for x64-based Systems | 5053594 (Security Update) |
Important | Security Feature Bypass | Yes |
| Windows 10 Version 1809 for 32-bit Systems | 5053596 (Security Update) |
Important | Security Feature Bypass | Yes |
| Windows 10 Version 1809 for x64-based Systems | 5053596 (Security Update) |
Important | Security Feature Bypass | Yes |
| Windows 10 Version 21H2 for 32-bit Systems | 5053606 (Security Update) |
Important | Security Feature Bypass | Yes |
| Windows 10 Version 21H2 for ARM64-based Systems | 5053606 (Security Update) |
Important | Security Feature Bypass | Yes |
| Windows 10 Version 21H2 for x64-based Systems | 5053606 (Security Update) |
Important | Security Feature Bypass | Yes |
| Windows 10 Version 22H2 for 32-bit Systems | 5053606 (Security Update) |
Important | Security Feature Bypass | Yes |
| Windows 10 Version 22H2 for ARM64-based Systems | 5053606 (Security Update) |
Important | Security Feature Bypass | Yes |
| Windows 10 Version 22H2 for x64-based Systems | 5053606 (Security Update) |
Important | Security Feature Bypass | Yes |
| Windows 11 Version 22H2 for ARM64-based Systems | 5053602 (Security Update) |
Important | Security Feature Bypass | Yes |
| Windows 11 Version 22H2 for x64-based Systems | 5053602 (Security Update) |
Important | Security Feature Bypass | Yes |
| Windows 11 Version 23H2 for ARM64-based Systems | 5053602 (Security Update) |
Important | Security Feature Bypass | Yes |
| Windows 11 Version 23H2 for x64-based Systems | 5053602 (Security Update) |
Important | Security Feature Bypass | Yes |
| Windows 11 Version 24H2 for ARM64-based Systems 5053598 (Security Update) 5053636 (SecurityHotpatchUpdate) Important Security Feature Bypass 5051987 5052105 Base: 7.0 Temporal: 6.5 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 10.0.26100.3476 10.0.26100.3403 Yes None Windows 11 Version 24H2 for x64-based Systems 5053598 (Security Update) 5053636 (SecurityHotpatchUpdate) Important Security Feature Bypass 5051987 5052105 Base: 7.0 Temporal: 6.5 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 10.0.26100.3476 10.0.26100.3403 Yes None Windows Server 2008 for 32-bit Systems Service Pack 2 5053888 (Monthly Rollup) 5053995 (Security Only) Important Security Feature Bypass 5052038 Base: 7.0 Temporal: 6.5 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.0.6003.23168 Yes None Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) 5053888 (Monthly Rollup) 5053995 (Security Only) Important Security Feature Bypass 5052038 Base: 7.0 Temporal: 6.5 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.0.6003.23168 Yes None Windows Server 2008 for x64-based Systems Service Pack 2 5053888 (Monthly Rollup) 5053995 (Security Only) Important Security Feature Bypass 5052038 Base: 7.0 Temporal: 6.5 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.0.6003.23168 Yes None Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) 5053888 (Monthly Rollup) 5053995 (Security Only) Important Security Feature Bypass 5052038 Base: 7.0 Temporal: 6.5 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.0.6003.23168 Yes None Windows Server 2008 R2 for x64-based Systems Service Pack 1 5053620 (Monthly Rollup) 5053627 (Security Only) Important Security Feature Bypass 5052016 Base: 7.0 Temporal: 6.5 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.1.7601.27618 Yes None Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) 5053620 (Monthly Rollup) 5053627 (Security Only) Important Security Feature Bypass 5052016 Base: 7.0 Temporal: 6.5 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.1.7601.27618 Yes None Windows Server 2012 | 5053886 (Monthly Rollup) |
Important | Security Feature Bypass | Yes |
| Windows Server 2012 (Server Core installation) | 5053886 (Monthly Rollup) |
Important | Security Feature Bypass | Yes |
| Windows Server 2012 R2 | 5053887 (Monthly Rollup) |
Important | Security Feature Bypass | Yes |
| Windows Server 2012 R2 (Server Core installation) | 5053887 (Monthly Rollup) |
Important | Security Feature Bypass | Yes |
| Windows Server 2016 | 5053594 (Security Update) |
Important | Security Feature Bypass | Yes |
| Windows Server 2016 (Server Core installation) | 5053594 (Security Update) |
Important | Security Feature Bypass | Yes |
| Windows Server 2019 | 5053596 (Security Update) |
Important | Security Feature Bypass | Yes |
| Windows Server 2019 (Server Core installation) | 5053596 (Security Update) |
Important | Security Feature Bypass | Yes |
| Windows Server 2022 5053603 (Security Update) 5053638 (SecurityHotpatchUpdate) Important Security Feature Bypass 5051979 5052106 Base: 7.0 Temporal: 6.5 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 10.0.20348.3328 10.0.20348.3270 Yes None Windows Server 2022 (Server Core installation) 5053603 (Security Update) 5053638 (SecurityHotpatchUpdate) Important Security Feature Bypass 5051979 5052106 Base: 7.0 Temporal: 6.5 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 10.0.20348.3328 10.0.20348.3270 Yes None Windows Server 2022, 23H2 Edition (Server Core installation) | 5053599 (Security Update) |
Important | Security Feature Bypass | Yes |
Patches
| Article | Type | Restart |
|---|---|---|
5053618 |
Security Update | Yes |
5053594 |
Security Update | Yes |
5053596 |
Security Update | Yes |
5053606 |
Security Update | Yes |
5053602 |
Security Update | Yes |
5053886 |
Monthly Rollup | Yes |
5053887 |
Monthly Rollup | Yes |
5053599 |
Security Update | Yes |
Patch Diff
Security feature bypass (CWE-707 improper neutralization) in Microsoft Management Console mmc.exe, EXPLOITED IN THE WILD as the 'MSC EvilTwin' technique (Important, SFB, AV:L, UI:R, AC:H, CVSS 7.0, E:F). CAMCDoc::ScOnOpenDocument opens a .msc console and resolves a localized/MUI copy via ScGetMuiPath; for untrusted sources it is meant to refuse the silent open via _IsFileSourceUntrustworthy (which zone-checks a path through URLMON CoInternetCreateSecurityManager). PRE (.3323): the untrusted-source check was applied to the PRIMARY path only, NOT to the MUI-resolved path, so an attacker could stage an 'evil twin' - a benign primary .msc alongside a malicious localized .msc in the MUI location - and MMC would load the attacker's localized console without the trust check firing, bypassing the security feature. Diff of mmc.exe 10.0.26100.3323 -> .3476 (Mar 11 2025, KB5053598) confirms the fix: _IsFileSourceUntrustworthy body is unchanged but its refcount rises 2 -> 4 - gated behind the new CFR flag Feature_220736827, ScOnOpenDocument now runs the untrusted-source check on the MUI-resolved path (local_90 from ScGetMuiPath) and routes to ScFromMMC (failure, ShowIncompatibleFileMessage) when the source is untrusted, closing the EvilTwin bypass.
| Function | Address | Change | Note |
|---|---|---|---|
CAMCDoc::ScOnOpenDocument |
code change |
code (adds untrusted-source check on the MUI-resolved path, CFR-gated) | Pre: _IsFileSourceUntrustworthy applied to the primary path only (Feature_2408386874). Post (Feature_220736827): the check is also run on the MUI/localized path (local_90 from ScGetMuiPath); untrusted sources are rejected via ScFromMMC. _IsFileSourceUntrustworthy refcount 2 -> 4. |
_IsFileSourceUntrustworthy |
code change |
code (unchanged body; now called on additional paths) | Body ratio 1.0 (unchanged) - zone-checks a path via URLMON CoInternetCreateSecurityManager. The security-relevant change is that it is now invoked on the MUI-resolved path, not that its logic changed. |
Feature_220736827 |
gate |
added (CFR gate) | New CFR flag gating the untrusted-source check on the MUI/localized path in ScOnOpenDocument; when disabled, the pre-patch behaviour (primary-path check only, under Feature_2408386874) remains. |
Attack Path
An 'evil twin' localized .msc loads via MUI resolution without the untrusted-source check (MSC EvilTwin bypass)
Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.
Exploits & PoC
2 public PoCsUnverified third-party code
Public proof-of-concept repositories aggregated from PoC-in-GitHub. They are not reviewed and may be incomplete, non-functional, or malicious — inspect the code before running anything.
| Repository | Stars | Published | Description |
|---|---|---|---|
| mbanyamer/MSC-EvilTwin-Local-Privilege-Escalation | 4 | 2025-11-22 | CVE-2025-26633 (CVSS 7.8) – Zero-day MMC .msc EvilTwin LPE actively exploited by Water Gamayun APT. PoC creates local admin via malicious MSC file on unpatched Windows 10/11/Server. Patched March 2025 |
| sandsoncosta/CVE-2025-26633 | 2 | 2025-04-08 |
Detection Rules
Acknowledgments
Aliakbar Zahravi with Trend Micro