CVE-2025-26633
HIGH
7,0
Source: [email protected]
Attack Vector: local
Attack Complexity: high
Privileges Required: none
User Interaction: required
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high
Description
AI Translation Available
Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,1003
Percentile
0,9th
Updated
EPSS Score Trend (Last 90 Days)
707
Improper Neutralization
IncompleteCommon Consequences
Security Scopes Affected:
Other
Potential Impacts:
Other
Applicable Platforms
All platforms may be affected
Operating System
Windows 10 1809 by Microsoft
Version Range Affected
To
10.0.17763.7009
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x86:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Windows 10 21H2 by Microsoft
Version Range Affected
To
10.0.19044.5608
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Windows 10 1607 by Microsoft
Version Range Affected
To
10.0.14393.7876
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Windows Server 2008 by Microsoft
CPE Identifier
View Detailed Analysis
cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x64:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Windows 10 1607 by Microsoft
Version Range Affected
To
10.0.14393.7876
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x86:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Windows 10 1507 by Microsoft
Version Range Affected
To
10.0.10240.20947
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x86:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Windows 10 21H2 by Microsoft
Version Range Affected
To
10.0.19044.5608
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x86:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Windows 10 1809 by Microsoft
Version Range Affected
To
10.0.17763.7009
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Windows 10 1507 by Microsoft
Version Range Affected
To
10.0.10240.20947
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x64:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Windows 10 21H2 by Microsoft
Version Range Affected
To
10.0.19044.5608
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:arm64:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Windows 11 23H2 by Microsoft
Version Range Affected
To
10.0.22631.5039
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:arm64:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Windows 11 22H2 by Microsoft
Version Range Affected
To
10.0.22621.5039
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:x64:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Windows Server 2022 23H2 by Microsoft
Version Range Affected
To
10.0.25398.1486
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:x64:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Windows Server 2012 by Microsoft
CPE Identifier
View Detailed Analysis
cpe:2.3:o:microsoft:windows_server_2012:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Windows 10 22H2 by Microsoft
Version Range Affected
To
10.0.19045.5608
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:arm64:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Windows Server 2022 by Microsoft
Version Range Affected
To
10.0.20348.3270
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Windows Server 2008 by Microsoft
CPE Identifier
View Detailed Analysis
cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:x86:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Windows Server 2008 by Microsoft
CPE Identifier
View Detailed Analysis
cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Windows 11 24H2 by Microsoft
Version Range Affected
To
10.0.26100.3403
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:arm64:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Windows 10 22H2 by Microsoft
Version Range Affected
To
10.0.19045.5608
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x86:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Windows Server 2016 by Microsoft
Version Range Affected
To
10.0.14393.7876
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Windows 11 22H2 by Microsoft
Version Range Affected
To
10.0.22621.5039
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:microsoft:windows_11_22h2:*:*:*:*:*:*:arm64:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Windows Server 2025 by Microsoft
Version Range Affected
To
10.0.26100.3403
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:x64:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Windows Server 2019 by Microsoft
Version Range Affected
To
10.0.17763.7009
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Windows Server 2012 by Microsoft
CPE Identifier
View Detailed Analysis
cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Windows 11 24H2 by Microsoft
Version Range Affected
To
10.0.26100.3403
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:microsoft:windows_11_24h2:*:*:*:*:*:*:x64:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Windows 11 23H2 by Microsoft
Version Range Affected
To
10.0.22631.5039
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:microsoft:windows_11_23h2:*:*:*:*:*:*:x64:*
Common Platform Enumeration - Standardized vulnerability identification
Operating System
Windows 10 22H2 by Microsoft
Version Range Affected
To
10.0.19045.5608
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:o:microsoft:windows_10_22h2:*:*:*:*:*:*:x64:*
Common Platform Enumeration - Standardized vulnerability identification
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025…
https://www.vicarius.io/vsociety/posts/cve-2025-26633-security-feature-bypass-i…
https://www.vicarius.io/vsociety/posts/cve-2025-26633-security-feature-bypass-i…
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26633