CyberICT

CVE-2025-26633

Microsoft · Published March 11, 2025

CVSS v3.1

HIGH
Patch availableGet patch

Description

Microsoft Management Console (MMC) security feature bypass allows attackers to execute malicious .msc files by bypassing Windows file reputation checks. Used by Water Gamayun (UAT-5647) threat group.

Affected Products

  • Windows 10/11 (all versions)
  • Windows Server 2016/2019/2022/2025

CVSS Vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

Related Advisories