What you need to know
CVE-2025-26633 is a vulnerability in the Microsoft Windows Management Console (MMC) that lets an unauthorised attacker bypass a security feature when they have local access to the system. The flaw has a CVSS score of 7.0, placing it in the high severity band, and it has been confirmed to be used in real‑world attacks, including ransomware campaigns. If your environment runs any flavour of Windows that still carries the unpatched MMC component, you should treat this as a priority.
Related remediation guides
Other vulnerabilities in the same family or affecting the same products:
- CVE-2025-49844 – Immediate actions for Redis administrators
- CVE-2025-5777 – What it is, risk, and how to remediate Citrix NetScaler ADC/Gateway
- CVE-2025-61884 – Immediate steps for Oracle E‑Business Suite Configurator SSRF
For the wider picture, our Known Exploited Vulnerabilities tracker lists every flaw CISA has confirmed under active attack.
Who should be concerned
Any organisation that runs Windows desktops or servers – from legacy Windows 10 builds to the latest Windows 11 releases – is in scope. The risk is greatest on machines that allow local users to launch MMC snap‑ins, which is the default configuration on most corporate PCs. If you manage workstations, laptops, or server workloads that are joined to Active Directory, you need to verify the state of each host.
Technical overview
MMC is the framework that hosts administrative tools such as Event Viewer, Device Manager and Group Policy Editor. The vulnerability falls into the class of “improper neutralisation” bugs. In plain terms, the code that checks whether a user is allowed to perform a privileged action does not correctly filter or validate the input it receives. An attacker who can run a malicious snap‑in can trick MMC into thinking a security check has passed when it has not.
The exact details of the exploit chain have not been published, but the impact is clear: once the bypass is achieved, the attacker can elevate their privileges or disable security controls that would otherwise stop them. Because the attack requires the ability to run code locally, the most common scenario is a malicious insider or a piece of malware that has already gained a foothold on the machine.
Microsoft’s advisory notes that the flaw is “locally exploitable”. That means remote attackers cannot trigger it directly over the network, but any malware that lands on a workstation – for example via a phishing attachment – can immediately take advantage of the weakness.
How to tell if you are exposed
The only reliable way to know whether a host is vulnerable is to compare its build number with the list of fixed releases. The table below (automatically generated from the NVD) shows the last vulnerable build for each Windows branch and the build that contains the fix.
Run one of the following commands on each machine and note the build identifier that is returned. If the build matches any entry in the “up to” column of the table, the system is still vulnerable.
systeminfo | findstr /B /C:"OS Version"– works in a standard command prompt.(Get-ComputerInfo).WindowsVersion– PowerShell one‑liner that returns the full version string.winver– opens the graphical dialog that displays the build number.
Do not rely on the Windows Update UI alone; it may show that updates are available without indicating whether the specific MMC fix is included.
Remediation steps
The recommended action is to upgrade to the patched release for your branch. Microsoft has released a cumulative update that contains the fix. Apply the update through your normal patching pipeline – whether you use WSUS, Microsoft Endpoint Configuration Manager, or a third‑party patch manager.
After the update is installed, reboot the machine to ensure the new MMC binaries are loaded. Verify the build number again with the commands above; it should now appear in the “fixed” column of the table.
If you run a centralised update service, make sure the deployment package includes the security rollup that addresses CVE-2025-26633. Do not cherry‑pick individual patches unless you are certain they contain the MMC fix.
While the update is being rolled out, you can apply a short‑term mitigation by restricting who can launch MMC snap‑ins. On a domain‑joined computer, set the following Group Policy:
- Computer Configuration → Administrative Templates → Windows Components → Microsoft Management Console → “Restrict users from opening MMC snap‑ins” – enable this setting and list the allowed snap‑ins only.
Alternatively, you can rename the mmc.exe binary temporarily, but that will break legitimate administration tools, so use it only as a last resort.
If a patch cannot be applied immediately
There are situations where a machine cannot be taken offline for a reboot – for example a critical production server. In those cases, combine the following controls:
- Enforce least‑privilege accounts. Ensure that only trusted administrators have local logon rights.
- Enable Windows Defender Application Control or a similar code‑integrity solution to block unsigned MMC snap‑ins.
- Audit the event log for MMC activity. Look for Event ID 4096, which records MMC launch attempts.
- Consider disabling the MMC console entirely on the host if it is not needed for day‑to‑day operations. This can be done via the same Group Policy mentioned above.
These steps do not remove the vulnerability, but they raise the bar for an attacker who has already gained a foothold.
What to do after you have patched
Once the update is applied, run a quick scan with your vulnerability scanner to confirm that CVE-2025-26633 is no longer reported. Record the build number in your asset inventory and mark the host as compliant.
Because the vulnerability has been used in ransomware campaigns, it is a good idea to review recent alerts for any signs of MMC abuse. Look for processes that spawn mmc.exe from unusual locations or with unexpected command‑line arguments.
Finally, update any internal documentation that references the affected Windows builds. Replace the old version range with a note that the system is now on the patched branch.
Bottom line
CVE-2025-26633 is a high‑severity, locally exploitable flaw in the Windows Management Console. It has been seen in the wild and is linked to ransomware activity. The fix is already available from Microsoft; the quickest way to protect your environment is to apply the latest cumulative update for the Windows branch you are running. Use the commands above to verify your build, apply the patch, and, if you cannot reboot straight away, tighten local privileges and restrict MMC usage. Treat this as an urgent item on your patching backlog – the longer a vulnerable system stays online, the more attractive it becomes to an attacker.
Affected versions
Straight from the NVD record for CVE-2025-26633. If your build is inside one of these ranges, treat it as vulnerable.
| Product | Affected range | Fixed in |
|---|---|---|
windows_10_1507 |
* up to 10.0.10240.20947 | 10.0.10240.20947 |
windows_10_1607 |
* up to 10.0.14393.7876 | 10.0.14393.7876 |
windows_10_1809 |
* up to 10.0.17763.7009 | 10.0.17763.7009 |
windows_10_21h2 |
* up to 10.0.19044.5608 | 10.0.19044.5608 |
windows_10_22h2 |
* up to 10.0.19045.5608 | 10.0.19045.5608 |
windows_11_22h2 |
* up to 10.0.22621.5039 | 10.0.22621.5039 |
windows_11_23h2 |
* up to 10.0.22631.5039 | 10.0.22631.5039 |
windows_11_24h2 |
* up to 10.0.26100.3403 | 10.0.26100.3403 |
windows_server_2016 |
* up to 10.0.14393.7876 | 10.0.14393.7876 |
windows_server_2019 |
* up to 10.0.17763.7009 | 10.0.17763.7009 |
windows_server_2022 |
* up to 10.0.20348.3270 | 10.0.20348.3270 |
windows_server_2022_23h2 |
* up to 10.0.25398.1486 | 10.0.25398.1486 |

