
Proof-of-concept exploit for CVE-2025-26633 (MSC EvilTwin) demonstrating remote command execution via malicious .msc files with HTML/ActiveX in Microsoft Management Console.
This PoC simulates the CVE-2025-26633 vulnerability, discovered by Trend Micro, which exploits the loading of malicious .msc files for remote command execution via HTML with ActiveX in MMC context.
This PoC is for educational purposes and should be performed only in controlled and authorized environments. I am not responsible for any misuse of the information contained in this repository.