HomeSecurityEncryptHub exploited zero-day vulnerability in Microsoft Management Console

EncryptHub exploited zero-day vulnerability in Microsoft Management Console

The EncryptHub was linked to attacks exploiting a zero-day vulnerability in the Microsoft Management Console targeting Windows systems. The bug was patched by Microsoft this month.

Microsoft Management Console vulnerability EncryptHub zero-day vulnerability

The vulnerability was discovered by Trend Micro researcher Aliakbar Zahravi and is tracked as CVE-2025-26633 . It allows for security feature bypass and is related to the way MSC files are handled on vulnerable devices.

See also: Fixes for Windows zero-day vulnerability affecting NTLM

Attackers can exploit the vulnerability to bypass Windows file reputation protections and execute code. This is possible because the user is not warned before loading unexpected MSC files on unpatched devices.

“In an email attack scenario, an attacker could exploit the vulnerability by sending a specially crafted file to the user and convincing them to open the file,” Microsoft said when it released its Patch Tuesday bulletin March. “In a web-based attack scenario, an attacker could host a website (or leverage a compromised website that accepts or hosts user-provided content) that contains a specially crafted file that is designed to exploit the vulnerability.”

See also: Authentication bypass vulnerability in VMware Windows Tools

In attacks that Trend Micro researchers discovered before reporting the vulnerability to Microsoft, the EncryptHub group exploited a vulnerability in the Microsoft Management Console to execute malicious code and extract data from compromised systems. The attackers were able to deploy multiple malicious payloads, including the EncryptHub stealer, DarkWisp backdoor, SilentPrism backdoor, Stealc, Rhadamanthys stealer, and the MSC EvilTwin trojan loader.

EncryptHub exploited zero-day vulnerability in Microsoft Management Console
EncryptHub exploited zero-day vulnerability in Microsoft Management Console

According to researchers, the campaign is under active development and uses multiple delivery methods and payloads, all designed to maintain persistence and steal sensitive data.

See also: Google Chrome: Fixed serious zero-day vulnerability

To protect against such threats, the following measures are recommended:

  1. Apply security updates immediately: Install all recent Microsoft updates to fix known vulnerabilities.
  2. User education: Be aware of the threats associated with unexpected file attachments or links, especially from unknown sources.
  3. Use security software: Implement reliable antivirus and anti-malware programs to detect and prevent attacks.
  4. Restrict user rights: Give users only the rights necessary to perform their tasks, thereby reducing the risk of exploitation.
  5. Apply security policies: Set policies to block or warn when opening .msc files from untrusted sources.

Constant vigilance and regular updates of systems and users are critical to protecting against sophisticated threats such as those associated with the EncryptHub group.

Source: www.bleepingcomputer.com

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS