Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/sandsoncosta/cve-2025-26633
Payload GenerationExploitationWeb Application ExploitationPenetration TestingLearning & EducationRed Teaming
GitHubsandsoncosta/cve-2025-26633

CVE-2025-26633

Proof-of-concept exploit for CVE-2025-26633 (MSC EvilTwin) demonstrating remote command execution via malicious .msc files with HTML/ActiveX in Microsoft Management Console.

View Repository
2121 year agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2025-26633 - MSC EvilTwin PoC

Proof of Concept (PoC) for CVE-2025-26633 vulnerability exploiting Microsoft Management Console (MMC)


About

This PoC simulates the CVE-2025-26633 vulnerability, discovered by Trend Micro, which exploits the loading of malicious .msc files for remote command execution via HTML with ActiveX in MMC context.

Notice

This PoC is for educational purposes and should be performed only in controlled and authorized environments. I am not responsible for any misuse of the information contained in this repository.

Links

  • Full Article: CVE-2025-26633: Como simular e identificar o ataque MSC EvilTwin
Download Tool