Junglewise Threat Intelligence

CVE-2025-26633: Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability

CVE-2025-26633 · Severity: critical · CVSS 7 · Exploited in the wild · Published 2025-03-11

Technologies: Microsoft Windows Server 2008, Microsoft Windows Server 2025, Microsoft Windows, Microsoft Windows Server 2016, Microsoft Windows Server 2022 23h2, Microsoft Windows Server 2019, Microsoft Windows Server 2012, Microsoft Windows 10. Vendors: Microsoft.

Executive brief

Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass security features. Exploitation requires local access and user interaction, but it has been observed being exploited in the wild.

Affected products

  • Microsoft Windows Server 2008 SP2, R2 SP1
  • Microsoft Windows Server 2012 R2
  • Microsoft Windows Server 2016 up to (excluding) 10.0.14393.7876
  • Microsoft Windows Server 2019 up to (excluding) 10.0.17763.7009
  • Microsoft Windows Server 2022 23H2 up to (excluding) 10.0.25398.1486
  • Microsoft Windows Server 2025 up to (excluding) 10.0.26100.3403
  • Microsoft Windows 10 1507, 1607, 1809, 21H2, 22H2

Timeline

  • 2025-03-11: disclosed
  • 2025-03-11: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats