CVE-2025-26633
published 2025-03-11CVE-2025-26633: Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.
PriorityP185high7CVSS 3.1
AVLACHPRNUIRSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2025-04-01
Exploited in the wild
EPSS
31.89%
98.1th percentile
Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.
Affected
47 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10_1507 | < 10.0.10240.20947 | 10.0.10240.20947 |
| microsoft | windows_10_1607 | < 10.0.14393.7876 | 10.0.14393.7876 |
| microsoft | windows_10_1809 | < 10.0.17763.7009 | 10.0.17763.7009 |
| microsoft | windows_10_21h2 | < 10.0.19044.5608 | 10.0.19044.5608 |
| microsoft | windows_10_22h2 | < 10.0.19045.5608 | 10.0.19045.5608 |
| microsoft | windows_10_version_1507 | >= 10.0.10240.0 < 10.0.10240.20947 | 10.0.10240.20947 |
| microsoft | windows_10_version_1607 | >= 10.0.14393.0 < 10.0.14393.7876 | 10.0.14393.7876 |
| microsoft | windows_10_version_1809 | >= 10.0.17763.0 < 10.0.17763.7009 | 10.0.17763.7009 |
| microsoft | windows_10_version_21h2 | >= 10.0.19044.0 < 10.0.19044.5608 | 10.0.19044.5608 |
| microsoft | windows_10_version_22h2 | >= 10.0.19045.0 < 10.0.19045.5608 | 10.0.19045.5608 |
| microsoft | windows_11_22h2 | < 10.0.22621.5039 | 10.0.22621.5039 |
| microsoft | windows_11_23h2 | < 10.0.22631.5039 | 10.0.22631.5039 |
| microsoft | windows_11_24h2 | < 10.0.26100.3403 | 10.0.26100.3403 |
| microsoft | windows_11_version_22h2 | >= 10.0.22621.0 < 10.0.22621.5039 | 10.0.22621.5039 |
| microsoft | windows_11_version_22h3 | >= 10.0.22631.0 < 10.0.22631.5039 | 10.0.22631.5039 |
| microsoft | windows_11_version_23h2 | >= 10.0.22631.0 < 10.0.22631.5039 | 10.0.22631.5039 |
| microsoft | windows_11_version_24h2 | >= 10.0.26100.0 < 10.0.26100.3476 | 10.0.26100.3476 |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.27618 | 6.1.7601.27618 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.6003.0 < 6.0.6003.23168 | 6.0.6003.23168 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.25368 | 6.2.9200.25368 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.22470 | 6.3.9600.22470 |
| microsoft | windows_server_2016 | < 10.0.14393.7876 | 10.0.14393.7876 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.7876 | 10.0.14393.7876 |
Detection & IOCsextracted from sources · hover to see the quote
- →Detect creation of mock trusted directories with trailing spaces mimicking system paths, specifically 'C:\Windows \System32' (with space before backslash) and 'C:\Windows \System32\en-US', used by the MSC EvilTwin loader to hijack MUI path resolution in mmc.exe. ↗
- →Monitor mmc.exe loading WmiMgmt.msc from a non-standard en-US MUI path (i.e., from a directory with a trailing space in the path) rather than the legitimate C:\Windows\System32\en-US path. ↗
- →Detect invoker.exe (a renamed runnerw.exe from IntelliJ) executing PowerShell with hidden execution and bypass flags — a LOLBin abuse technique used by Water Gamayun to evade detection. ↗
- →Detect persistence via mshta.exe combined with VBScript auto-run registry entries (non-admin) or scheduled tasks (admin) created by SilentPrism backdoor to download and execute remote payloads. ↗
- →Hunt for blank HTML pages served from attacker infrastructure that contain hidden JavaScript executing PowerShell download cradles — used by Water Gamayun to deliver DarkWisp, Stealc, Rhadamanthys, and AnyDesk. ↗
- ·C&C infrastructure is short-lived; the IP 82[.]115[.]223[.]182 and associated domains (encrypthub.net/org) may already be offline. New servers are regularly deployed to replace them. ↗
- ·The MSC EvilTwin technique (CVE-2025-26633) was patched by Microsoft on March 11, 2025. Systems without this patch remain vulnerable to mmc.exe loading malicious .msc files from spoofed MUI paths. ↗
- ·The campaign is under active development; payloads, delivery methods, and infrastructure are continuously evolving, meaning IOCs may have limited shelf life. ↗
- ·DarkWisp build identifiers are unique per stub; the 'encrypthub' identifier observed is specific to the analyzed sample and may differ across deployments. ↗
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
vulncheck7.0HIGH
cisa7.0HIGH
vendor_msrc7.0HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-8xfh-434c-qfv7: Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally
ghsa_unreviewed·2025-03-11
CVE-2025-26633 [HIGH] CWE-707 GHSA-8xfh-434c-qfv7: Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally
Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.
VulnCheck
Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability
vulncheck·2025·CVSS 7.0
CVE-2025-26633 [HIGH] CWE-707 Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability
Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability
Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally.
Affected: Microsoft Windows
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Known Ransomware Campaign Use: Known
Exploitation References: https://api.msrc.microsoft.com/cvrf/v3.0/cvrf/2025-Mar; https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26633; https://www.cisa.gov/sites/default/files/feeds/known_expl
CISA
Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability
cisa·2025-03-11·CVSS 7.0
CVE-2025-26633 [HIGH] CWE-707 Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability
Vulnerability: Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability
Affected: Microsoft Windows
Microsoft Windows Management Console (MMC) contains an improper neutralization vulnerability that allows an unauthorized attacker to bypass a security feature locally.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: https://msrc.microsoft.com/update-guide/en-US/vulnerability/CVE-2025-26633 ; https://nvd.nist.gov/vuln/detail/CVE-2025-26633
Remediation Due Date: 2025-04-01
Microsoft
Microsoft Management Console Security Feature Bypass Vulnerability
vendor_msrc·2025-03-11·CVSS 7.0
CVE-2025-26633 [HIGH] CWE-707 Microsoft Management Console Security Feature Bypass Vulnerability
Microsoft Management Console Security Feature Bypass Vulnerability
Description: Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.
FAQ: According to the CVSS metric, the attack complexity is high (AC:H). What does that mean for this vulnerability?
Successful exploitation of this vulnerability requires an attacker to take additional actions prior to exploitation to prepare the target environment.
FAQ: How could an attacker exploit the vulnerability?
In an email or instant message attack scenario, the attacker could send the targeted user a specially crafted file that is designed to exploit the vulnerability.
In any case an attacker would have no way to force a user to view attacker-controlled content. Instead, an
No detection rules found.
Greynoiseio
The Noise in the Silence: Unmasking CISA's Hidden KEV Ransomware Updates
blogs_greynoiseio·2026-02-02
The Noise in the Silence: Unmasking CISA's Hidden KEV Ransomware Updates
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Find out immediately if an asset communicates with a malicious IP address
Vulnerability Prioritization Get real-time insight into active exploitation trends to better understand risk and severity
SOC Efficiency Filter out noisy, low priority and false-positive alerts from mass internet scanners
Incident Investigation Add context to incidents to speed the determinations of scope and timelines
Threat Hunting Quickly identify anomalous behavior and enrich your threat hunting campaigns
Why GreyNoise
CVE Disclosure Early Warning Get an early warning when traffic spikes indicate a high likelihood of new disclosures
Compromised Asset Detection Fin
Tenable
Patch Tuesday 2025 Year In Review
blogs_tenable·2025-12-10
Patch Tuesday 2025 Year In Review
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Zscaler
In-Depth Analysis: Water Gamayun APT Multi-Stage Attack Uncovered
blogs_zscaler·2025-11-25
In-Depth Analysis: Water Gamayun APT Multi-Stage Attack Uncovered
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
Bleepingcomputer
EncryptHub's dual life: Cybercriminal vs Windows bug-bounty researcher
blogs_bleepingcomputer·2025-04-07
EncryptHub's dual life: Cybercriminal vs Windows bug-bounty researcher
## EncryptHub's dual life: Cybercriminal vs Windows bug-bounty researcher
## Bill Toulas
A new report by Outpost24 researchers has now linked the EncryptHub threat actor with SkorikARI after the threat actor allegedly infected himself and exposed their credentials.
This exposure allowed the researchers to link the threat actor to various online accounts and expose the profile of a person who vacillates between being a cybersecurity researcher and a cybercriminal.
One of the exposed accounts is SkorikARI, which the hacker used to disclose the two mentioned zero-day vulnerabilities to Microsoft, contributing to Windows security.
Hector Garcia, Security Analyst at Outpost24, told BleepingComputer that the link of SkorikARI to EncryptHub is based on multiple pieces of evidence, making up
Trendmicro
Water Gamayun missbraucht Zero Day-Lücke in MMC
blogs_trendmicro·2025-04-01·CVSS 7.0
CVE-2025-26633 [HIGH] Water Gamayun missbraucht Zero Day-Lücke in MMC
Cyberrisiken
## Water Gamayun missbraucht Zero Day-Lücke in MMC
Durch den Missbrauch einer Schwachstelle im MMC-Framework, CVE-2025-26633), hat der Bedrohungsakteur Water Gamayun eine effiziente Methode entwickelt, um bösartigen Code auf infizierten Rechnern auszuführen. Wir haben die fiesen Techniken analysiert.
By: Aliakbar Zahravi Apr 01, 2025 Lesezeit: ( Wörter)
Save to Folio
Weitere Einzelheiten liefert der Originalbeitrag .
Vorgetäuschte vertrauenswürdige Verzeichnisse
Der dritte Ansatz besteht darin, vorgetäuschte Verzeichnisse zu erstellen, die den Standard-Systempfaden ähneln, indem Leerzeichen oder Sonderzeichen an den Namen angehängt werden. Wenn die Pfadvalidierungslogik einer Anwendung Leerzeichen bei Zeichenfolgenvergleichen nicht richtig behandelt, kann sie das geände
Checkpoint
31st March – Threat Intelligence Report
blogs_checkpoint·2025-04-01
CVE-2025-2783 31st March – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 31st March – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 31st March, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
New York University (NYU) suffered a cyber-attack which resulted in the exposure of over 3 million applicants’ data, including names, test scores, majors, and zip codes. The hacker redirected NYU’s website to display this information, alleging the university’s continued use of race-sensitive admissions policies despite the Su
Trendmicro
A Deep Dive into Water Gamayun's Arsenal and Infrastructure
blogs_trendmicro·2025-03-28·CVSS 7.0
CVE-2025-26633 [HIGH] A Deep Dive into Water Gamayun's Arsenal and Infrastructure
Exploits & Vulnerabilities
# A Deep Dive into Water Gamayun’s Arsenal and Infrastructure
Trend Research discusses the delivery methods, custom payloads, and techniques used by Water Gamayun, the suspected Russian threat actor abusing a zero-day vulnerability in the Microsoft Management Console framework (CVE-2025-26633) to execute malicious code on infected machines.
By: Aliakbar Zahravi, Ahmed Mohamed Ibrahim
2025/03/28
Read time: ( words)
Save to Folio
## Summary
- Water Gamayun, which exploits the MSC EvilTwin zero-day vulnerability (CVE-2025-26633) to compromise systems and exfiltrate data, uses custom payloads and data exfiltration techniques. Businesses can be severely impacted by such an attack as a result of data theft and operational disruption.
- The threat actor deploys p
Trendmicro
A Deep Dive into Water Gamayun's Arsenal and Infrastructure
blogs_trendmicro·2025-03-28·CVSS 7.0
CVE-2025-26633 [HIGH] A Deep Dive into Water Gamayun's Arsenal and Infrastructure
Exploits & Vulnerabilities
## A Deep Dive into Water Gamayun’s Arsenal and Infrastructure
Trend Research discusses the delivery methods, custom payloads, and techniques used by Water Gamayun, the suspected Russian threat actor abusing a zero-day vulnerability in the Microsoft Management Console framework (CVE-2025-26633) to execute malicious code on infected machines.
By: Aliakbar Zahravi, Ahmed Mohamed Ibrahim Mar 28, 2025 Read time: ( words)
Save to Folio
Subsequently, on August 5, 2024, researchers published an analysis detailing this attack vector, shedding light on the malicious activity associated with this campaign. The GitHub repository was later taken down, and its contents were relocated to the encrypthub.(net/org) domain. The attackers transitioned their operations to this
Trendmicro
A Deep Dive into Water Gamayun's Arsenal and Infrastructure
blogs_trendmicro·2025-03-28·CVSS 7.0
CVE-2025-26633 [HIGH] A Deep Dive into Water Gamayun's Arsenal and Infrastructure
Exploits & Vulnerabilities
## A Deep Dive into Water Gamayun’s Arsenal and Infrastructure
Trend Research discusses the delivery methods, custom payloads, and techniques used by Water Gamayun, the suspected Russian threat actor abusing a zero-day vulnerability in the Microsoft Management Console framework (CVE-2025-26633) to execute malicious code on infected machines.
By: Aliakbar Zahravi, Ahmed Mohamed Ibrahim 2025/03/28 Read time: ( words)
Save to Folio
Subsequently, on August 5, 2024, researchers published an analysis detailing this attack vector, shedding light on the malicious activity associated with this campaign. The GitHub repository was later taken down, and its contents were relocated to the encrypthub.(net/org) domain. The attackers transitioned their operations to this do
Trendmicro
A Deep Dive into Water Gamayun's Arsenal and Infrastructure
blogs_trendmicro·2025-03-28·CVSS 7.0
CVE-2025-26633 [HIGH] A Deep Dive into Water Gamayun's Arsenal and Infrastructure
Exploits y vulnerabilidades
## A Deep Dive into Water Gamayun’s Arsenal and Infrastructure
Trend Research discusses the delivery methods, custom payloads, and techniques used by Water Gamayun, the suspected Russian threat actor abusing a zero-day vulnerability in the Microsoft Management Console framework (CVE-2025-26633) to execute malicious code on infected machines.
By: Aliakbar Zahravi, Ahmed Mohamed Ibrahim Mar 28, 2025 Read time: ( words)
Save to Folio
Subsequently, on August 5, 2024, researchers published an analysis detailing this attack vector, shedding light on the malicious activity associated with this campaign. The GitHub repository was later taken down, and its contents were relocated to the encrypthub.(net/org) domain. The attackers transitioned their operations to this
Trendmicro
CVE-2025-26633: How Water Gamayun Weaponizes MUIPath using MSC EvilTwin
blogs_trendmicro·2025-03-25·CVSS 7.0
CVE-2025-26633 [HIGH] CVE-2025-26633: How Water Gamayun Weaponizes MUIPath using MSC EvilTwin
Exploits & Vulnerabilities
## CVE-2025-26633: How Water Gamayun Weaponizes MUIPath using MSC EvilTwin
Trend Research identified Russian threat actor Water Gamayun exploiting CVE-2025-26633, a zero-day vulnerability in the Microsoft Management Console that attackers exploit to execute malicious code and exfiltrate data.
By: Aliakbar Zahravi 2025/03/25 Read time: ( words)
Save to Folio
A single .msc file can include references to multiple snap-ins (Figure 3). These files are scriptable, allowing users to create, modify, and use them to open MMC with a predefined set of tools and configurations.
When executing an .msc file through mmc.exe, the ScOnOpenDocument function calls the scGetMuiPath function, which uses the GetFileMUIPath Windows API to retrieve the MUI file if it exists.
If M
Trendmicro
CVE-2025-26633: How Water Gamayun Weaponises MUIPath using MSC EvilTwin
blogs_trendmicro·2025-03-25·CVSS 7.0
CVE-2025-26633 [HIGH] CVE-2025-26633: How Water Gamayun Weaponises MUIPath using MSC EvilTwin
Exploits & Vulnerabilities
## CVE-2025-26633: How Water Gamayun Weaponises MUIPath using MSC EvilTwin
Trend Research identified Russian threat actor Water Gamayun exploiting CVE-2025-26633, a zero-day vulnerability in the Microsoft Management Console that attackers exploit to execute malicious code and exfiltrate data.
By: Aliakbar Zahravi Mar 25, 2025 Read time: ( words)
Save to Folio
A single .msc file can include references to multiple snap-ins (Figure 3). These files are scriptable, allowing users to create, modify, and use them to open MMC with a predefined set of tools and configurations.
When executing an .msc file through mmc.exe, the ScOnOpenDocument function calls the scGetMuiPath function, which uses the GetFileMUIPath Windows API to retrieve the MUI file if it exists.
If
Trendmicro
CVE-2025-26633: How Water Gamayun Weaponizes MUIPath using MSC EvilTwin
blogs_trendmicro·2025-03-25·CVSS 7.0
CVE-2025-26633 [HIGH] CVE-2025-26633: How Water Gamayun Weaponizes MUIPath using MSC EvilTwin
Exploits y vulnerabilidades
## CVE-2025-26633: How Water Gamayun Weaponizes MUIPath using MSC EvilTwin
Trend Research identified Russian threat actor Water Gamayun exploiting CVE-2025-26633, a zero-day vulnerability in the Microsoft Management Console that attackers exploit to execute malicious code and exfiltrate data.
By: Aliakbar Zahravi Mar 25, 2025 Read time: ( words)
Save to Folio
A single .msc file can include references to multiple snap-ins (Figure 3). These files are scriptable, allowing users to create, modify, and use them to open MMC with a predefined set of tools and configurations.
When executing an .msc file through mmc.exe, the ScOnOpenDocument function calls the scGetMuiPath function, which uses the GetFileMUIPath Windows API to retrieve the MUI file if it exists.
I
Trendmicro
CVE-2025-26633: How Water Gamayun Weaponizes MUIPath using MSC EvilTwin
blogs_trendmicro·2025-03-25·CVSS 7.0
CVE-2025-26633 [HIGH] CVE-2025-26633: How Water Gamayun Weaponizes MUIPath using MSC EvilTwin
Exploits & Vulnerabilities
## CVE-2025-26633: How Water Gamayun Weaponizes MUIPath using MSC EvilTwin
Trend Research identified Russian threat actor Water Gamayun exploiting CVE-2025-26633, a zero-day vulnerability in the Microsoft Management Console that attackers exploit to execute malicious code and exfiltrate data.
By: Aliakbar Zahravi Mar 25, 2025 Read time: ( words)
Save to Folio
A single .msc file can include references to multiple snap-ins (Figure 3). These files are scriptable, allowing users to create, modify, and use them to open MMC with a predefined set of tools and configurations.
When executing an .msc file through mmc.exe, the ScOnOpenDocument function calls the scGetMuiPath function, which uses the GetFileMUIPath Windows API to retrieve the MUI file if it exists.
If
Trendmicro
CVE-2025-26633: How Water Gamayun Weaponizes MUIPath using MSC EvilTwin
blogs_trendmicro·2025-03-25·CVSS 7.0
CVE-2025-26633 [HIGH] CVE-2025-26633: How Water Gamayun Weaponizes MUIPath using MSC EvilTwin
Exploits & Vulnerabilities
# CVE-2025-26633: How Water Gamayun Weaponizes MUIPath using MSC EvilTwin
Trend Research identified Russian threat actor Water Gamayun exploiting CVE-2025-26633, a zero-day vulnerability in the Microsoft Management Console that attackers exploit to execute malicious code and exfiltrate data.
By: Aliakbar Zahravi
2025/03/25
Read time: ( words)
Save to Folio
Summary
- Trend Research uncovered a campaign by the Russian threat actor Water Gamayun that exploits a zero-day vulnerability in the Microsoft Management Console framework to execute malicious code, named MSC EvilTwin (CVE-2025-26633).
- In this attack the threat actor manipulates .msc files and the Multilingual User Interface Path (MUIPath) to download and execute malicious payload, maintain persistenc
Bleepingcomputer
Microsoft patches Windows Kernel zero-day exploited since 2023
blogs_bleepingcomputer·2025-03-12·CVSS 7.8
CVE-2025-24983 [HIGH] Microsoft patches Windows Kernel zero-day exploited since 2023
## Microsoft patches Windows Kernel zero-day exploited since 2023
## Sergiu Gatlan
ESET said on Tuesday that a zero-day exploit targeting the CVE-2025-24983 vulnerability was "first seen in the wild" in March 2023 on systems backdoored using PipeMagic malware.
This exploit targets only older Windows versions (Windows Server 2012 R2 and Windows 8.1) that Microsoft no longer supports. However, the vulnerability also affects newer Windows versions, including the still-supported Windows Server 2016 and Windows 10 systems running Windows 10 build 1809 and earlier.
"The Use-After-Free (UAF) vulnerability is related to improper memory usage during software operation. This can lead to software crashes, execution of malicious code (including remotely), privilege escalation, or data corruption,"
Krebs
Microsoft: 6 Zero-Days in March 2025 Patch Tuesday
blogs_krebs·2025-03-12·CVSS 7.0
CVE-2025-24991 [HIGH] Microsoft: 6 Zero-Days in March 2025 Patch Tuesday
Microsoft today issued more than 50 security updates for its various Windows operating systems, including fixes for a whopping six zero-day vulnerabilities that are already seeing active exploitation.
Two of the zero-day flaws include CVE-2025-24991 and CVE-2025-24993, both vulnerabilities in NTFS, the default file system for Windows and Windows Server. Both require the attacker to trick a target into mounting a malicious virtual hard disk. CVE-2025-24993 would lead to the possibility of local code execution, while CVE-2025-24991 could cause NTFS to disclose portions of memory.
Microsoft credits researchers at ESET with reporting the zero-day bug labeled CVE-2025-24983, an elevation of privilege vulnerability in older versions of Windows. ESET said the exploit was deployed via the PipeMa
Qualys
Microsoft and Adobe Patch Tuesday, March 2025 Security Update Review
blogs_qualys·2025-03-11
Microsoft and Adobe Patch Tuesday, March 2025 Security Update Review
## Table of Contents
Microsoft Patch Tuesday for March 2025
Adobe Patches for March 2025
Zero-day Vulnerabilities Patched in March Patch Tuesday Edition
Critical Severity Vulnerabilities Patched in March Patch Tuesday Edition
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Discover and Prioritize Vulnerabilities inVulnerability Management, Detection & Response (VMDR)
Rapid Response withPatch Management (PM)
EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
Risk Reduction via TruRisk Eliminate
Qualys Monthly Webinar Series
March 2025 Patch Tuesday is here, and Microsoft has rolled out critical security updates that address multiple vulnerabilities across its product suite. Here’s a quick breakdown of what you need to know.
## Microsoft Patch Tu
Talos
Microsoft Patch Tuesday for March 2025 — Snort rules and prominent vulnerabilities
blogs_talos·2025-03-11·CVSS 7.8
CVE-2025-26633 [HIGH] Microsoft Patch Tuesday for March 2025 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for March 2025 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for March of 2025 which includes 57 vulnerabilities affecting a range of products, including 6 that Microsoft marked as “critical”.
There are six vulnerabilities that Microsoft has observed being exploited in the wild. CVE-2025-26633 is a Remoted Code Execution (RCE) vulnerability in Microsoft’s Management Console. Two information disclosure vulnerabilities, CVE-2025-24984 and CVE-2025-24991 , and one RCE vulnerability, CVE-2025-24993 , in Windows NTFS were observed being exploited in the wild. Microsoft also patched, CVE-2025-24985 , another RCE exploited in the wild in the Windows Fast FAT system driver. An Elevation of Privilege (EOP) vulnerability,
Tenable
Microsoft’s March 2025 Patch Tuesday Addresses 56 CVEs (CVE-2025-26633, CVE-2025-24983, CVE-2025-24993)
blogs_tenable·2025-03-11·CVSS 7.0
[HIGH] Microsoft’s March 2025 Patch Tuesday Addresses 56 CVEs (CVE-2025-26633, CVE-2025-24983, CVE-2025-24993)
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
Krebs
Microsoft: 6 Zero-Days in March 2025 Patch Tuesday
blogs_krebs·2025-03-11·CVSS 7.0
CVE-2025-24991 [HIGH] Microsoft: 6 Zero-Days in March 2025 Patch Tuesday
Microsoft today issued more than 50 security updates for its various Windows operating systems, including fixes for a whopping six zero-day vulnerabilities that are already seeing active exploitation.
Two of the zero-day flaws include CVE-2025-24991 and CVE-2025-24993 , both vulnerabilities in NTFS , the default file system for Windows and Windows Server. Both require the attacker to trick a target into mounting a malicious virtual hard disk. CVE-2025-24993 would lead to the possibility of local code execution, while CVE-2025-24991 could cause NTFS to disclose portions of memory.
Microsoft credits researchers at ESET with reporting the zero-day bug labeled CVE-2025-24983 , an elevation of privilege vulnerability in older versions of Windows. ESET said the exploit was deployed via the Pip
Talos
Microsoft Patch Tuesday for March 2025 — Snort rules and prominent vulnerabilities
blogs_talos·2025-03-11·CVSS 7.8
CVE-2025-26633 [HIGH] Microsoft Patch Tuesday for March 2025 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for March of 2025 which includes 57 vulnerabilities affecting a range of products, including 6 that Microsoft marked as “critical”.
There are six vulnerabilities that Microsoft has observed being exploited in the wild. CVE-2025-26633 is a Remoted Code Execution (RCE) vulnerability in Microsoft’s Management Console. Two information disclosure vulnerabilities, CVE-2025-24984 and CVE-2025-24991, and one RCE vulnerability, CVE-2025-24993, in Windows NTFS were observed being exploited in the wild. Microsoft also patched, CVE-2025-24985, another RCE exploited in the wild in the Windows Fast FAT system driver. An Elevation of Privilege (EOP) vulnerability, CVE-2025-24983, was also discovered being exploited in the wild, in Windows’ win32 Kernel
Qualys
Microsoft and Adobe Patch Tuesday, March 2025 Security Update Review | Qualys
blogs_qualys·2025-03-11
Microsoft and Adobe Patch Tuesday, March 2025 Security Update Review | Qualys
#### Table of Contents
- Microsoft Patch Tuesday for March 2025
- Adobe Patches for March 2025
- Zero-day Vulnerabilities Patched in March Patch Tuesday Edition
- Critical Severity Vulnerabilities Patched in March Patch Tuesday Edition
- Other Microsoft Vulnerability Highlights
- Microsoft Release Summary
- Discover and Prioritize Vulnerabilities inVulnerability Management, Detection & Response (VMDR)
- Rapid Response withPatch Management (PM)
- EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
- Risk Reduction via TruRisk Eliminate
- Qualys Monthly Webinar Series
March 2025 Patch Tuesday is here, and Microsoft has rolled out critical security updates that address multiple vulnerabilities across its product suite. Here’s a quick breakdown of what you need to know.
## Micr
Bleepingcomputer
Microsoft March 2025 Patch Tuesday fixes 7 zero-days, 57 flaws
blogs_bleepingcomputer·2025-03-11·CVSS 7.0
[HIGH] Microsoft March 2025 Patch Tuesday fixes 7 zero-days, 57 flaws
## Microsoft March 2025 Patch Tuesday fixes 7 zero-days, 57 flaws
## Lawrence Abrams
23 Elevation of Privilege Vulnerabilities
3 Security Feature Bypass Vulnerabilities
23 Remote Code Execution Vulnerabilities
4 Information Disclosure Vulnerabilities
1 Denial of Service Vulnerabilities
3 Spoofing Vulnerabilities
The above numbers do not include Mariner flaws and 10 Microsoft Edge vulnerabilities fixed earlier this month.
To learn more about the non-security updates released today, you can review our dedicated articles on the Windows 11 KB5053598 & KB5053602 cumulative updates and the Windows 10 KB5053606 update .
## Six actively exploited zero-days
This month's Patch Tuesday fixes six actively exploited zero-days and one that was publicly exposed, for a total of seven zero-days.
Crowdstrike
March 2025 Patch Tuesday: Updates and Analysis
blogs_crowdstrike·CVSS 7.5
CVE-2026-20929 [HIGH] March 2025 Patch Tuesday: Updates and Analysis
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
STARDUST CHOLLIMA Likely Compromises Axios npm Package Apr 01, 2026
Falcon for IT Supports Windows Secure Boot Certificate Lifecycle Management Apr 01, 2026
Detecting CVE-2026-20929: Kerberos Authentication Relay via CNAME Abuse Mar 31, 2026
How Charlotte AI AgentWorks Fuels Security's Agentic Ecosystem Mar 25, 2026
Video Highlights the 4 Key Steps to Successful Incident Response Dec 02, 2019
Helping Non-Security Stakeholders Understand ATT&CK in 10 Minutes or Less [VI
Recorded Future
Rate My Rizz: Elevating Cyber Resilience Beyond Compliance
blogs_recorded_future
Rate My Rizz: Elevating Cyber Resilience Beyond Compliance
# Rate My Rizz
RSA is always a good opportunity to reconnect with industry friends—2025 was no exception. Beneath the marketing avalanche of “AI-enabled everything,” one theme stuck out in conversations with CISOs and defensive leaders: the mounting time and energy spent on cyber audits, reporting, and remediation.
These Enterprise Risk Management (ERM) and Governance, Risk, and Compliance (GRC) efforts are especially demanding in regulated industries. But with mandates like NIS2 and DORA taking effect in Europe—and domestic frameworks like SOX, SOC2, and CMMC still in play—security leaders are spending more time with audit committees than ever before.
## Compliance Theater: Starring the Risk Register
In enterprises, defensive resource allocations are often adjudicated by committees an
Recorded Future
Rate My Rizz: Elevating Cyber Resilience Beyond Compliance
blogs_recorded_future
Rate My Rizz: Elevating Cyber Resilience Beyond Compliance
## Rate My Rizz
RSA is always a good opportunity to reconnect with industry friends—2025 was no exception. Beneath the marketing avalanche of “AI-enabled everything,” one theme stuck out in conversations with CISOs and defensive leaders: the mounting time and energy spent on cyber audits, reporting, and remediation.
These Enterprise Risk Management (ERM) and Governance, Risk, and Compliance (GRC) efforts are especially demanding in regulated industries. But with mandates like NIS2 and DORA taking effect in Europe—and domestic frameworks like SOX , SOC2 , and CMMC still in play—security leaders are spending more time with audit committees than ever before.
## Compliance Theater: Starring the Risk Register
In enterprises, defensive resource allocations are often adjudicated by committees
Zscaler
CXO Monthly Roundup, November 2025: React2Shell, insights into how Zscaler Deception fights AI-driven threats, vulnerabilities uncovered by ThreatLabz, and Water Gamayun APT attack analysis | CXO Revo
blogs_zscaler·CVSS 10.0
[CRITICAL] CXO Monthly Roundup, November 2025: React2Shell, insights into how Zscaler Deception fights AI-driven threats, vulnerabilities uncovered by ThreatLabz, and Water Gamayun APT attack analysis | CXO Revo
## CXO Monthly Roundup, November 2025: React2Shell, insights into how Zscaler Deception fights AI-driven threats, vulnerabilities uncovered by ThreatLabz, and Water Gamayun APT attack analysis
Deepen Desai
Contributor
Zscaler
## Dec 12, 2025
Highlights from the Zscaler ThreatLabz team's November 2025 research.
The CXO Monthly Roundup provides the latest Zscaler ThreatLabz research and critical updates, featuring coverage of the React2Shell vulnerability, insights into how Zscaler Deception fights AI-driven threats, key discoveries from Zscaler threat analysis, a detailed examination of a Water Gamayun APT attack, and the latest threat intelligence on DanaBot and TransferLoader.
## React2Shell (CVE-2025-55182) vulnerability
We will begin by examining an urgent and critical security
arXiv
CyberThreat-Eval: Can Large Language Models Automate Real-World Threat Research?
arxiv_fulltext·2026-03-10
CyberThreat-Eval: Can Large Language Models Automate Real-World Threat Research?
## Abstract
Analyzing Open Source Intelligence (OSINT) from large volumes of data is critical for drafting and publishing comprehensive CTI reports. This process usually follows a three-stage workflow---triage, deep search and TI drafting. While Large Language Models (LLMs) offer a promising route toward automation, existing benchmarks still have limitations. These benchmarks often consist of tasks that do not reflect real-world analyst workflows. For example, human analysts rarely receive tasks in the form of multiple-choice questions. Also, existing benchmarks often rely on model-centric metrics that emphasize lexical overlap rather than actionable, detailed insights essential for security analysts. Moreover, they typically fail to cover the complete three-stage workflow. To address the
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26633https://www.vicarius.io/vsociety/posts/cve-2025-26633-security-feature-bypass-in-microsoft-management-console-detection-scripthttps://www.vicarius.io/vsociety/posts/cve-2025-26633-security-feature-bypass-in-microsoft-management-console-mitigation-scripthttps://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-26633
2025-03-11
Published
2025-03-11
Added to CISA KEV
Exploited in the wild