CISA KEV · catalog date Mar 11, 2025 · first observed Jul 19, 2026
Evidence dossier
CVE-2025-26633
Microsoft Management Console Security Feature Bypass Vulnerability
Exploited in the wild (CISA KEV since Mar 11, 2025). microsoft reports CVSS 3.1 7.0. EPSS estimates 30.4% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.
- State
- PUBLISHED
- Published
- Mar 11, 2025
- Updated
- Aug 5, 2026
- Evidence coverage
- 85%
Evidence chronology
What was known when
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAmicrosoftOriginal evidence ↗
Record text: Microsoft Management Console Security Feature Bypass Vulnerability
Inspect raw assertion
- Field
container- Value
- Microsoft Management Console Security Feature Bypass Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 30.39% probability · 98.09th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.303910000000; percentile 0.980930000000
FIRST EPSS · score date Aug 27, 2026 · 98.1th percentile · first observed Aug 27, 2026
microsoft · CVSS 3.1 · first observed Aug 6, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Microsoft Windows Management Console (MMC) Improper Neutralization Vulnerability
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
Microsoft Management Console Security Feature Bypass Vulnerability
Inspect raw assertion
- Field
container- Value
- Microsoft Management Console Security Feature Bypass Vulnerability
30.39% probability · 98.09th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.303910000000; percentile 0.980930000000
Applicability
Cited product scope
Grouped from 1 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
40 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.10240.0", "lessThan": "10.0.10240.20947", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.14393.0", "lessThan": "10.0.14393.7876", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.17763.0", "lessThan": "10.0.17763.7009", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.19044.0", "lessThan": "10.0.19044.5608", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.19045.0", "lessThan": "10.0.19045.5608", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.22621.0", "lessThan": "10.0.22621.5039", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.22631.0", "lessThan": "10.0.22631.5039", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.22631.0", "lessThan": "10.0.22631.5039", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.26100.0", "lessThan": "10.0.26100.3476", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.1.7601.0", "lessThan": "6.1.7601.27618", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.1.7601.0", "lessThan": "6.1.7601.27618", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.0.6003.0", "lessThan": "6.0.6003.23168", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.0.6003.0", "lessThan": "6.0.6003.23168", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.2.9200.0", "lessThan": "6.2.9200.25368", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.3.9600.0", "lessThan": "6.3.9600.22470", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.3.9600.0", "lessThan": "6.3.9600.22470", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "6.2.9200.0", "lessThan": "6.2.9200.25368", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.14393.0", "lessThan": "10.0.14393.7876", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.14393.0", "lessThan": "10.0.14393.7876", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.17763.0", "lessThan": "10.0.17763.7009", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.17763.0", "lessThan": "10.0.17763.7009", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.20348.0", "lessThan": "10.0.20348.3328", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.25398.0", "lessThan": "10.0.25398.1486", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.26100.0", "lessThan": "10.0.26100.3476", "versionType": "custom"}]Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "10.0.26100.0", "lessThan": "10.0.26100.3476", "versionType": "custom"}]Affected-product evidence
Accepted scope and product mapping
0 canonical links · 2 source-reported links
Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 25
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0d903655-79e9-4b47-968c-da7a0b56489118c03515-859d-407b-a80a-ce94d445a9601cc4d9b8-8dab-440a-8e6d-ad0788435abb2847665d-94f1-43c9-80a1-fcaf7b3aef822cc7ff68-b86c-4134-9257-1f972539d9992db1f646-a2f4-423d-9ba3-35c1c854ca2636baed99-ec82-4285-8a2a-fbdf30214ef5413491f0-0f95-4208-9375-d678eb658cbb44f6b083-6a5c-4591-9238-643642fcb9dd55e1844d-7be4-4e9b-a33c-a749c722ac905c009f98-7567-4f07-86aa-047df3afbd7e7009ae83-8a5e-41e5-b6e6-c8c892f463f272569da6-fb56-4300-b4d7-bf18032d6fafa9aacdeb-2d6d-417f-8da3-bd6a2cbca923adbb4049-ad7f-4cc6-926f-e29421499e8fb15fd65a-1613-408e-8978-fe856a5ab1e9ba3a8b0e-7fb3-4dd3-bae3-e21366a11a49cb027062-9857-48f4-879d-e04e4340e462cdfc65dc-7bcb-4ef0-935c-4ae2ace24d59d22e2c05-0bd7-4fd1-a626-c10bfc7a2ae4dcb28203-df90-4293-8e58-3387d6b23d55e3ebda7d-191c-417d-a038-36da221db09fe4c940af-3763-4442-9038-343405d18480ed223641-e493-4399-80c0-12def212e7c4ffa53b9b-9faf-470f-b6d2-a1d47401d7b8Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Nvd cpe vulnerable target
- Assertions
- 28
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
18f799fd-a981-427e-8cbd-1f4ed04dee871958a7b9-97cd-47eb-987c-59dc0bb782472c67079e-b6bb-4bea-ae78-ce17334470da3624f117-713b-4b9e-8016-71292464e75b3f5c8d6b-1aa7-4886-8fe4-b2fe031fc0c844f100b7-d5c4-4998-a271-e0dddf0259614c295c54-e7c3-4ea8-9782-4939122d9a6d5839b752-2690-4485-94aa-e04d680ca55e5bcde25d-5b42-46b8-8570-c5958f932f5561f73c32-cef5-44e9-874f-1c33d6203b12681ab2d5-aad5-43d7-8786-27e3e8c461396fbb15d3-936f-4fcd-a003-0c63fdeaa9dc75a3025f-8a51-4802-9985-7fb07f090e647649bff1-5f4e-4d27-ae80-0c626438840376ca7996-5a87-4e37-a1a8-1b72edbdc89a8e7328de-337a-41ef-a5e6-3df26f58ef8bb90e1bc6-ac73-4eab-a0a2-90762703a8e6bcbdb3d2-380b-4636-bcb0-36344e10d312bd471b50-4823-4a4b-a029-f667d2f3c860c176943a-1d57-4093-a590-e7d2ce2d8c47c317a682-9333-4965-ab53-de776660a4fdc652df0d-3c63-40be-9cca-bdc1d5d2dccfd464ac25-3432-46bf-8c2d-26975ffe7400daebdebb-25b5-458f-ba70-bd602594f3bcf1769714-def3-4497-8d58-29996425fcf7fba69f62-0173-494c-a13b-95683633a1dffe2cabb0-fbae-43ac-9d58-d97c6e25941ffe96032a-6b92-47c4-967c-cef82adc210aAssessments
CVSS by origin
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:CDirect CVE/CNA normalized decisions
microsoft
CVSS 3.1 · Primary · Original assertion · rank 1
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H/E:F/RL:O/RC:C- Validation
- Valid match
- Recomputed
- 7.0
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.