Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.
The product does not ensure or incorrectly ensures that structured messages or data are well-formed and that certain security properties are met before being read from an upstream component or sent to a downstream component.
Link | Tags |
---|---|
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-26633 | vendor advisory |
https://www.vicarius.io/vsociety/posts/cve-2025-26633-security-feature-bypass-in-microsoft-management-console-detection-script | exploit third party advisory |
https://www.vicarius.io/vsociety/posts/cve-2025-26633-security-feature-bypass-in-microsoft-management-console-mitigation-script | exploit third party advisory |