Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.
Published: 2025-03-11
Microsoft addresses 56 CVEs, including seven zero-day flaws, with six of those being exploited in the wild.
https://thehackernews.com/2025/04/microsoft-credits-encrypthub-hacker.html
https://thehackernews.com/2025/03/russian-hackers-exploit-cve-2025-26633.html
https://www.securityweek.com/russian-ransomware-gang-exploited-windows-zero-day-before-patch/
https://thehackernews.com/2025/03/encrypthub-exploits-windows-zero-day-to.html
https://www.trendmicro.com/en_us/research/25/c/cve-2025-26633-water-gamayun.html
https://www.securityweek.com/patch-tuesday-microsoft-patches-57-flaws-flags-six-active-zero-days/
Published: 2025-03-11
Updated: 2025-04-17
Named Vulnerability: MSC EvilTwinKnown Exploited Vulnerability (KEV)
Base Score: 6.2
Vector: CVSS2#AV:L/AC:H/Au:N/C:C/I:C/A:C
Severity: Medium
Base Score: 7
Vector: CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity: High
EPSS: 0.04289