cbcvebase.
CVE-2025-26633
published 2025-03-11

CVE-2025-26633: Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.

PriorityP185high7CVSS 3.1
AVLACHPRNUIRSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2025-04-01
Exploited in the wild
EPSS
30.39%
98.2th percentile
Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.

Affected

47 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10_1507< 10.0.10240.2094710.0.10240.20947
microsoftwindows_10_1607< 10.0.14393.787610.0.14393.7876
microsoftwindows_10_1809< 10.0.17763.700910.0.17763.7009
microsoftwindows_10_21h2< 10.0.19044.560810.0.19044.5608
microsoftwindows_10_22h2< 10.0.19045.560810.0.19045.5608
microsoftwindows_10_version_1507>= 10.0.10240.0 < 10.0.10240.2094710.0.10240.20947
microsoftwindows_10_version_1607>= 10.0.14393.0 < 10.0.14393.787610.0.14393.7876
microsoftwindows_10_version_1809>= 10.0.17763.0 < 10.0.17763.700910.0.17763.7009
microsoftwindows_10_version_21h2>= 10.0.19044.0 < 10.0.19044.560810.0.19044.5608
microsoftwindows_10_version_22h2>= 10.0.19045.0 < 10.0.19045.560810.0.19045.5608
microsoftwindows_11_22h2< 10.0.22621.503910.0.22621.5039
microsoftwindows_11_23h2< 10.0.22631.503910.0.22631.5039
microsoftwindows_11_24h2< 10.0.26100.340310.0.26100.3403
microsoftwindows_11_version_22h2>= 10.0.22621.0 < 10.0.22621.503910.0.22621.5039
microsoftwindows_11_version_22h3>= 10.0.22631.0 < 10.0.22631.503910.0.22631.5039
microsoftwindows_11_version_23h2>= 10.0.22631.0 < 10.0.22631.503910.0.22631.5039
microsoftwindows_11_version_24h2>= 10.0.26100.0 < 10.0.26100.347610.0.26100.3476
microsoftwindows_server_2008——
microsoftwindows_server_2008_r2_service_pack_1>= 6.1.7601.0 < 6.1.7601.276186.1.7601.27618
microsoftwindows_server_2008_service_pack_2>= 6.0.6003.0 < 6.0.6003.231686.0.6003.23168
microsoftwindows_server_2012——
microsoftwindows_server_2012>= 6.2.9200.0 < 6.2.9200.253686.2.9200.25368
microsoftwindows_server_2012_r2>= 6.3.9600.0 < 6.3.9600.224706.3.9600.22470
microsoftwindows_server_2016< 10.0.14393.787610.0.14393.7876
microsoftwindows_server_2016>= 10.0.14393.0 < 10.0.14393.787610.0.14393.7876

Detection & IOCsextracted from sources · hover to see the quote

ip82[.]115[.]223[.]182↗
urlhxxps://82[.]115.223.182/encrypthub/ram/↗
hashcbb84155467087c4da2ec411463e4af379582bb742ce7009156756482868859c↗
hash983506186590f7118cb507d29f12f163afb536a03e6d0f4fb441df8afe49ede1↗
hash0ac748baaad6017e331a8d99aae9e5449a96ba76fb7374f5d8c678ae52b7db9f↗
hashbad43a1c8ba1dacf3daf82bc30a0673f9bc2675ea6cdedd34624ffc933b959f4↗
hash079b7f03c727de92c3fcb7d3b9b9fea6d1e9ffdcd60dc9a360af90ce7b4b5cc6↗
hash5752efa219c7e42cb104917f38c146e1f747d14230be0e64a5e87c20e82075bb↗
hash2a5f9198f1e563688a2081b746bdaf48d897ec0ae96dfafc15cd5cd52c25e8f2↗
hash91aa7642a301ad6f46a6e466d89b601270aac64b7b6a5661436f7f9b5d804e89↗
filenameDingTalk_v7.6.38.122510801.msi↗
filenameQQTalk.msi↗
filenameVooV Meeting.msi↗
filenameworker.ps1↗
filenameminer.ps1↗
filenamerunner.ps1↗
filenameram.exe↗
filenameinvoker.exe↗
filenameskotes.exe↗
filenameaxplong.exe↗
filenameWmiMgmt.msc↗
filenameencrypted.ps1↗
filenamefickle_payload.ps1↗
filenameram.ps1↗
pathC:\Windows \System32\↗
pathC:\Windows \System32\en-US↗
port8080↗
port8081↗
url/receive_result↗
url/send_notification?↗
commandCOMMAND|d2hvYW1p↗
processrunnerw.exe↗
processmmc.exe↗
  • →Detect creation of mock trusted directories with trailing spaces mimicking system paths, specifically 'C:\Windows \System32' (with space before backslash) and 'C:\Windows \System32\en-US', used by the MSC EvilTwin loader to hijack MUI path resolution in mmc.exe. ↗
  • →Monitor mmc.exe loading WmiMgmt.msc from a non-standard en-US MUI path (i.e., from a directory with a trailing space in the path) rather than the legitimate C:\Windows\System32\en-US path. ↗
  • →Detect invoker.exe (a renamed runnerw.exe from IntelliJ) executing PowerShell with hidden execution and bypass flags — a LOLBin abuse technique used by Water Gamayun to evade detection. ↗
  • →Detect persistence via mshta.exe combined with VBScript auto-run registry entries (non-admin) or scheduled tasks (admin) created by SilentPrism backdoor to download and execute remote payloads. ↗
  • →Hunt for blank HTML pages served from attacker infrastructure that contain hidden JavaScript executing PowerShell download cradles — used by Water Gamayun to deliver DarkWisp, Stealc, Rhadamanthys, and AnyDesk. ↗
  • ·C&C infrastructure is short-lived; the IP 82[.]115[.]223[.]182 and associated domains (encrypthub.net/org) may already be offline. New servers are regularly deployed to replace them. ↗
  • ·The MSC EvilTwin technique (CVE-2025-26633) was patched by Microsoft on March 11, 2025. Systems without this patch remain vulnerable to mmc.exe loading malicious .msc files from spoofed MUI paths. ↗
  • ·The campaign is under active development; payloads, delivery methods, and infrastructure are continuously evolving, meaning IOCs may have limited shelf life. ↗
  • ·DarkWisp build identifiers are unique per stub; the 'encrypthub' identifier observed is specific to the analyzed sample and may differ across deployments. ↗

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
vulncheck7.0HIGH
cisa7.0HIGH
vendor_msrc7.0HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.