Important CVSS 7 EPSS 0.30391 ⚠️ Exploited in the wild 🔬 Patch diffed 2025-03 archive

Executive Summary

Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.

Overview

7
CVSS HIGH
Important
MS Severity
Exploited
MS Exploit Status
Exploitation Detected
MS Exploit Likelihood
Category Security Feature Bypass
Released Mar 11 2025
Last Updated Mar 11 2025
Publicly Disclosed No
CISA KEV Listed (added 2025-03-11)
Known Exploits None Known
EPSS Score 0.30391 — 0.98069 percentile
NVD CVSS 7 HIGH — matches MSRC

CVSS Vector

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C
ATTACK VECTOR
Local
ATTACK COMPLEXITY
High
PRIVILEGES REQUIRED
None
USER INTERACTION
Required
SCOPE
Unchanged
CONFIDENTIALITY
High
INTEGRITY
High
AVAILABILITY
High
EXPLOIT CODE MATURITY
Functional
REMEDIATION LEVEL
Official Fix
REPORT CONFIDENCE
Confirmed
Temporal Score: 6.5

EPSS Score

0.30391
probability of exploitation in the next 30 days
0.98069 percentile - updated 2026-08-14
View on FIRST.org

Affected Products

25 affected products
Product KB Article Severity Impact Restart Required
Windows 10 for 32-bit Systems 5053618 (Security Update) Important Security Feature Bypass Yes
Windows 10 for x64-based Systems 5053618 (Security Update) Important Security Feature Bypass Yes
Windows 10 Version 1607 for 32-bit Systems 5053594 (Security Update) Important Security Feature Bypass Yes
Windows 10 Version 1607 for x64-based Systems 5053594 (Security Update) Important Security Feature Bypass Yes
Windows 10 Version 1809 for 32-bit Systems 5053596 (Security Update) Important Security Feature Bypass Yes
Windows 10 Version 1809 for x64-based Systems 5053596 (Security Update) Important Security Feature Bypass Yes
Windows 10 Version 21H2 for 32-bit Systems 5053606 (Security Update) Important Security Feature Bypass Yes
Windows 10 Version 21H2 for ARM64-based Systems 5053606 (Security Update) Important Security Feature Bypass Yes
Windows 10 Version 21H2 for x64-based Systems 5053606 (Security Update) Important Security Feature Bypass Yes
Windows 10 Version 22H2 for 32-bit Systems 5053606 (Security Update) Important Security Feature Bypass Yes
Windows 10 Version 22H2 for ARM64-based Systems 5053606 (Security Update) Important Security Feature Bypass Yes
Windows 10 Version 22H2 for x64-based Systems 5053606 (Security Update) Important Security Feature Bypass Yes
Windows 11 Version 22H2 for ARM64-based Systems 5053602 (Security Update) Important Security Feature Bypass Yes
Windows 11 Version 22H2 for x64-based Systems 5053602 (Security Update) Important Security Feature Bypass Yes
Windows 11 Version 23H2 for ARM64-based Systems 5053602 (Security Update) Important Security Feature Bypass Yes
Windows 11 Version 23H2 for x64-based Systems 5053602 (Security Update) Important Security Feature Bypass Yes
Windows 11 Version 24H2 for ARM64-based Systems 5053598 (Security Update) 5053636 (SecurityHotpatchUpdate) Important Security Feature Bypass 5051987 5052105 Base: 7.0 Temporal: 6.5 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 10.0.26100.3476 10.0.26100.3403 Yes None Windows 11 Version 24H2 for x64-based Systems 5053598 (Security Update) 5053636 (SecurityHotpatchUpdate) Important Security Feature Bypass 5051987 5052105 Base: 7.0 Temporal: 6.5 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 10.0.26100.3476 10.0.26100.3403 Yes None Windows Server 2008 for 32-bit Systems Service Pack 2 5053888 (Monthly Rollup) 5053995 (Security Only) Important Security Feature Bypass 5052038 Base: 7.0 Temporal: 6.5 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.0.6003.23168 Yes None Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation) 5053888 (Monthly Rollup) 5053995 (Security Only) Important Security Feature Bypass 5052038 Base: 7.0 Temporal: 6.5 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.0.6003.23168 Yes None Windows Server 2008 for x64-based Systems Service Pack 2 5053888 (Monthly Rollup) 5053995 (Security Only) Important Security Feature Bypass 5052038 Base: 7.0 Temporal: 6.5 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.0.6003.23168 Yes None Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation) 5053888 (Monthly Rollup) 5053995 (Security Only) Important Security Feature Bypass 5052038 Base: 7.0 Temporal: 6.5 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.0.6003.23168 Yes None Windows Server 2008 R2 for x64-based Systems Service Pack 1 5053620 (Monthly Rollup) 5053627 (Security Only) Important Security Feature Bypass 5052016 Base: 7.0 Temporal: 6.5 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.1.7601.27618 Yes None Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation) 5053620 (Monthly Rollup) 5053627 (Security Only) Important Security Feature Bypass 5052016 Base: 7.0 Temporal: 6.5 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 6.1.7601.27618 Yes None Windows Server 2012 5053886 (Monthly Rollup) Important Security Feature Bypass Yes
Windows Server 2012 (Server Core installation) 5053886 (Monthly Rollup) Important Security Feature Bypass Yes
Windows Server 2012 R2 5053887 (Monthly Rollup) Important Security Feature Bypass Yes
Windows Server 2012 R2 (Server Core installation) 5053887 (Monthly Rollup) Important Security Feature Bypass Yes
Windows Server 2016 5053594 (Security Update) Important Security Feature Bypass Yes
Windows Server 2016 (Server Core installation) 5053594 (Security Update) Important Security Feature Bypass Yes
Windows Server 2019 5053596 (Security Update) Important Security Feature Bypass Yes
Windows Server 2019 (Server Core installation) 5053596 (Security Update) Important Security Feature Bypass Yes
Windows Server 2022 5053603 (Security Update) 5053638 (SecurityHotpatchUpdate) Important Security Feature Bypass 5051979 5052106 Base: 7.0 Temporal: 6.5 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 10.0.20348.3328 10.0.20348.3270 Yes None Windows Server 2022 (Server Core installation) 5053603 (Security Update) 5053638 (SecurityHotpatchUpdate) Important Security Feature Bypass 5051979 5052106 Base: 7.0 Temporal: 6.5 Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C 10.0.20348.3328 10.0.20348.3270 Yes None Windows Server 2022, 23H2 Edition (Server Core installation) 5053599 (Security Update) Important Security Feature Bypass Yes

Patches

8 patches
Article Type Restart
5053618 Security Update Yes
5053594 Security Update Yes
5053596 Security Update Yes
5053606 Security Update Yes
5053602 Security Update Yes
5053886 Monthly Rollup Yes
5053887 Monthly Rollup Yes
5053599 Security Update Yes

Patch Diff

ghidriff · mmc.exe (KB5053598)

Security feature bypass (CWE-707 improper neutralization) in Microsoft Management Console mmc.exe, EXPLOITED IN THE WILD as the 'MSC EvilTwin' technique (Important, SFB, AV:L, UI:R, AC:H, CVSS 7.0, E:F). CAMCDoc::ScOnOpenDocument opens a .msc console and resolves a localized/MUI copy via ScGetMuiPath; for untrusted sources it is meant to refuse the silent open via _IsFileSourceUntrustworthy (which zone-checks a path through URLMON CoInternetCreateSecurityManager). PRE (.3323): the untrusted-source check was applied to the PRIMARY path only, NOT to the MUI-resolved path, so an attacker could stage an 'evil twin' - a benign primary .msc alongside a malicious localized .msc in the MUI location - and MMC would load the attacker's localized console without the trust check firing, bypassing the security feature. Diff of mmc.exe 10.0.26100.3323 -> .3476 (Mar 11 2025, KB5053598) confirms the fix: _IsFileSourceUntrustworthy body is unchanged but its refcount rises 2 -> 4 - gated behind the new CFR flag Feature_220736827, ScOnOpenDocument now runs the untrusted-source check on the MUI-resolved path (local_90 from ScGetMuiPath) and routes to ScFromMMC (failure, ShowIncompatibleFileMessage) when the source is untrusted, closing the EvilTwin bypass.

Pre-patch version 10.0.26100.3323 Download
Post-patch version 10.0.26100.3476 Download
Function Address Change Note
CAMCDoc::ScOnOpenDocument code change code (adds untrusted-source check on the MUI-resolved path, CFR-gated) Pre: _IsFileSourceUntrustworthy applied to the primary path only (Feature_2408386874). Post (Feature_220736827): the check is also run on the MUI/localized path (local_90 from ScGetMuiPath); untrusted sources are rejected via ScFromMMC. _IsFileSourceUntrustworthy refcount 2 -> 4.
_IsFileSourceUntrustworthy code change code (unchanged body; now called on additional paths) Body ratio 1.0 (unchanged) - zone-checks a path via URLMON CoInternetCreateSecurityManager. The security-relevant change is that it is now invoked on the MUI-resolved path, not that its logic changed.
Feature_220736827 gate added (CFR gate) New CFR flag gating the untrusted-source check on the MUI/localized path in ScOnOpenDocument; when disabled, the pre-patch behaviour (primary-path check only, under Feature_2408386874) remains.
View full diff report View RCA report

Attack Path

An 'evil twin' localized .msc loads via MUI resolution without the untrusted-source check (MSC EvilTwin bypass)

Attack path for CVE-2025-26633 An 'evil twin' localized .msc loads via MUI resolution without the untrusted-source check (MSC EvilTwin bypass) 01 — ENTRY Attacker stages a paired primary + malicious localized (MUI) .msc A benign-looking primary .msc alongside a malicious localized console in the MUI/<lang> location. AC:H - the attacker must prepare this layout first. 02 — CONTROLLED INPUT Victim opens the crafted .msc in MMC CAMCDoc::ScOnOpenDocument resolves the localized copy via ScGetMuiPath. AV:L / UI:R (user opens the file after email/web enticement). 03 — MISSING CHECK Untrusted-source check skipped on the MUI path (CWE-707) Pre-patch _IsFileSourceUntrustworthy is applied to the primary path only, so the attacker's MUI-resolved console loads without the security-zone trust check - security feature bypass. 04 — IMPACT Malicious console executes -> code execution MMC loads and acts on the untrusted localized .msc (spawning attacker payloads), which the trust gate should have blocked. Exploited in the wild as MSC EvilTwin.

Derived from the patch delta: the checks added by the vendor identify which fields crossed a trust boundary unvalidated. Reachability and privilege are taken from the call chain in the RCA report.

Exploits & PoC

2 public PoCs
RepositoryStarsPublishedDescription
mbanyamer/MSC-EvilTwin-Local-Privilege-Escalation 4 2025-11-22 CVE-2025-26633 (CVSS 7.8) – Zero-day MMC .msc EvilTwin LPE actively exploited by Water Gamayun APT. PoC creates local admin via malicious MSC file on unpatched Windows 10/11/Server. Patched March 2025
sandsoncosta/CVE-2025-26633 2 2025-04-08

Detection Rules

Acknowledgments

Aliakbar Zahravi with Trend Micro