cbcvebase.
CVE-2025-26633
published 2025-03-11

CVE-2025-26633: Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.

PriorityP185high7CVSS 3.1
AVLACHPRNUIRSUCHIHAH
KEVITWEXPLOITRansomware
CISA Known Exploited Vulnerabilitydue 2025-04-01
Exploited in the wild
EPSS
31.89%
98.1th percentile
Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.

Affected

47 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10_1507< 10.0.10240.2094710.0.10240.20947
microsoftwindows_10_1607< 10.0.14393.787610.0.14393.7876
microsoftwindows_10_1809< 10.0.17763.700910.0.17763.7009
microsoftwindows_10_21h2< 10.0.19044.560810.0.19044.5608
microsoftwindows_10_22h2< 10.0.19045.560810.0.19045.5608
microsoftwindows_10_version_1507>= 10.0.10240.0 < 10.0.10240.2094710.0.10240.20947
microsoftwindows_10_version_1607>= 10.0.14393.0 < 10.0.14393.787610.0.14393.7876
microsoftwindows_10_version_1809>= 10.0.17763.0 < 10.0.17763.700910.0.17763.7009
microsoftwindows_10_version_21h2>= 10.0.19044.0 < 10.0.19044.560810.0.19044.5608
microsoftwindows_10_version_22h2>= 10.0.19045.0 < 10.0.19045.560810.0.19045.5608
microsoftwindows_11_22h2< 10.0.22621.503910.0.22621.5039
microsoftwindows_11_23h2< 10.0.22631.503910.0.22631.5039
microsoftwindows_11_24h2< 10.0.26100.340310.0.26100.3403
microsoftwindows_11_version_22h2>= 10.0.22621.0 < 10.0.22621.503910.0.22621.5039
microsoftwindows_11_version_22h3>= 10.0.22631.0 < 10.0.22631.503910.0.22631.5039
microsoftwindows_11_version_23h2>= 10.0.22631.0 < 10.0.22631.503910.0.22631.5039
microsoftwindows_11_version_24h2>= 10.0.26100.0 < 10.0.26100.347610.0.26100.3476
microsoftwindows_server_2008
microsoftwindows_server_2008_r2_service_pack_1>= 6.1.7601.0 < 6.1.7601.276186.1.7601.27618
microsoftwindows_server_2008_service_pack_2>= 6.0.6003.0 < 6.0.6003.231686.0.6003.23168
microsoftwindows_server_2012
microsoftwindows_server_2012>= 6.2.9200.0 < 6.2.9200.253686.2.9200.25368
microsoftwindows_server_2012_r2>= 6.3.9600.0 < 6.3.9600.224706.3.9600.22470
microsoftwindows_server_2016< 10.0.14393.787610.0.14393.7876
microsoftwindows_server_2016>= 10.0.14393.0 < 10.0.14393.787610.0.14393.7876

Detection & IOCsextracted from sources · hover to see the quote

ip82[.]115[.]223[.]182
urlhxxps://82[.]115.223.182/encrypthub/ram/
hashcbb84155467087c4da2ec411463e4af379582bb742ce7009156756482868859c
hash983506186590f7118cb507d29f12f163afb536a03e6d0f4fb441df8afe49ede1
hash0ac748baaad6017e331a8d99aae9e5449a96ba76fb7374f5d8c678ae52b7db9f
hashbad43a1c8ba1dacf3daf82bc30a0673f9bc2675ea6cdedd34624ffc933b959f4
hash079b7f03c727de92c3fcb7d3b9b9fea6d1e9ffdcd60dc9a360af90ce7b4b5cc6
hash5752efa219c7e42cb104917f38c146e1f747d14230be0e64a5e87c20e82075bb
hash2a5f9198f1e563688a2081b746bdaf48d897ec0ae96dfafc15cd5cd52c25e8f2
hash91aa7642a301ad6f46a6e466d89b601270aac64b7b6a5661436f7f9b5d804e89
filenameDingTalk_v7.6.38.122510801.msi
filenameQQTalk.msi
filenameVooV Meeting.msi
filenameworker.ps1
filenameminer.ps1
filenamerunner.ps1
filenameram.exe
filenameinvoker.exe
filenameskotes.exe
filenameaxplong.exe
filenameWmiMgmt.msc
filenameencrypted.ps1
filenamefickle_payload.ps1
filenameram.ps1
pathC:\Windows \System32\
pathC:\Windows \System32\en-US
port8080
port8081
url/receive_result
url/send_notification?
commandCOMMAND|d2hvYW1p
processrunnerw.exe
processmmc.exe
  • Detect creation of mock trusted directories with trailing spaces mimicking system paths, specifically 'C:\Windows \System32' (with space before backslash) and 'C:\Windows \System32\en-US', used by the MSC EvilTwin loader to hijack MUI path resolution in mmc.exe.
  • Monitor mmc.exe loading WmiMgmt.msc from a non-standard en-US MUI path (i.e., from a directory with a trailing space in the path) rather than the legitimate C:\Windows\System32\en-US path.
  • Detect invoker.exe (a renamed runnerw.exe from IntelliJ) executing PowerShell with hidden execution and bypass flags — a LOLBin abuse technique used by Water Gamayun to evade detection.
  • Detect persistence via mshta.exe combined with VBScript auto-run registry entries (non-admin) or scheduled tasks (admin) created by SilentPrism backdoor to download and execute remote payloads.
  • Hunt for blank HTML pages served from attacker infrastructure that contain hidden JavaScript executing PowerShell download cradles — used by Water Gamayun to deliver DarkWisp, Stealc, Rhadamanthys, and AnyDesk.
  • ·C&C infrastructure is short-lived; the IP 82[.]115[.]223[.]182 and associated domains (encrypthub.net/org) may already be offline. New servers are regularly deployed to replace them.
  • ·The MSC EvilTwin technique (CVE-2025-26633) was patched by Microsoft on March 11, 2025. Systems without this patch remain vulnerable to mmc.exe loading malicious .msc files from spoofed MUI paths.
  • ·The campaign is under active development; payloads, delivery methods, and infrastructure are continuously evolving, meaning IOCs may have limited shelf life.
  • ·DarkWisp build identifiers are unique per stub; the 'encrypthub' identifier observed is specific to the analyzed sample and may differ across deployments.

CVSS provenance

nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
vulncheck7.0HIGH
cisa7.0HIGH
vendor_msrc7.0HIGH
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.