ZeroHour

CVE-2025-26633

KEV ransomware PoC ×2mass

Local Security Feature Bypass in Microsoft Windows Management Console (MMC)

CISA: Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability

CVSS 3.1
7.0 high
EPSS
30%p98
Published
()
KEV added
AI analysis

Microsoft Windows Management Console (MMC) contains an improper neutralization flaw (CWE-707) that allows an unauthorized attacker to bypass a security feature locally. It is triggered when MMC processes specially crafted input during local use, letting the attacker sidestep a built-in Windows security control. The attacker gains evasion of that security feature, which is most valuable as one stage of a broader attack chain rather than as a standalone compromise. Virtually any organization running affected Microsoft Windows releases is affected, since MMC ships with Windows by default. The flaw is already being exploited in the wild: CISA added it to the KEV catalog on 2025-03-11 with known ransomware use, and EPSS places its 30-day exploitation probability at 30.4% (98th percentile), though no public proof-of-concept is known.

What to do: Apply Microsoft's security updates per vendor instructions as required under CISA KEV/BOD 22-01, prioritizing this patch given known ransomware use and the KEV deadline. Inventory Windows endpoints and servers for patch status and hunt for anomalous MMC execution until updates are applied; for cloud services, follow applicable BOD 22-01 guidance, and discontinue or mitigate use where patches are unavailable.

Affected
Microsoft Windows
Estimated exposure
mass1 billion+ Windows installations (MMC is a default Windows component) — Microsoft has publicly reported more than 1.4 billion monthly active Windows devices and MMC ships by default on Windows, so the potential exposure spans essentially all Windows desktop and server deployments.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Known
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows server 2008, windows server 2012, windows server 2016, windows server 2019
Weakness
CWE-707
Vector
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news