CVE-2025-26633
Microsoft · Published March 11, 2025
7.0
CVSS v3.1
HIGHCISA KEV — Federal agencies must patch by deadline
Actively exploited in the wild
Patch availableGet patch
Description
Microsoft Management Console (MMC) security feature bypass allows attackers to execute malicious .msc files by bypassing Windows file reputation checks. Used by Water Gamayun (UAT-5647) threat group.
Affected Products
- Windows 10/11 (all versions)
- Windows Server 2016/2019/2022/2025
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H