
CVE-2025-26633 (CVSS 7.8) – Zero-day MMC .msc EvilTwin LPE actively exploited by Water Gamayun APT. PoC creates local admin via malicious MSC file on unpatched Windows 10/11/Server. Patched March 2025. Authorized testing only.
Zero-day at time of disclosure (March 2025) – Actively exploited in the wild by Water Gamayun APT
ONLY FOR AUTHORIZED SECURITY TESTING AND RESEARCH
7.8 (High) – AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HThis repository contains a proof-of-concept exploit that demonstrates arbitrary command execution via a malicious .msc (MMC snap-in) file.
When a low-privileged user opens the crafted .msc file using mmc.exe, the embedded RunCommand action is executed with the user's privileges — allowing post-exploitation lateral movement or privilege escalation in certain attack chains.
The current PoC silently creates a local administrator account:
hackerP@ssw0rd123!python3 cve-2025-26633_poc.py