B
ä»é±äž
Microsoft Management Console (MMC) ã®èåŒ±æ§ (CVE-2025-26633) ãå©çšããæªæã®ãã .mscâŠ
ð äžèšã§ãããš
Microsoft Management Console (MMC) ã®èåŒ±æ§ (CVE-2025-26633) ãå©çšããæªæã®ãã .msc ãã¡ã€ã«ãéããŠããŒã«ã«ç®¡çè
ã¢ã«ãŠã³ããäœæããæ»æææ³ã§ãããã®è匱æ§ã¯ Water Gamayun APT ã«ãã£ãŠæªçšãããŠãããWindows 10, 11 ããã³ Windows Server ã®åºç¯ãªããŒãžã§ã³ã«åœ±é¿ããŸãããŠãŒã¶ãŒã现工ããããã¡ã€ã«ãèªã¿èŸŒãããšã§ãPowerShell çµç±ã§ç¹æš©ã¢ã«ãŠã³ããéãã«äœæãããŸãã察çãšããŠã2025幎3æã® Microsoft ããã (KB5053602 以é) ã®é©çšãæšå¥šãããŸãã
ð§æ³šæåèµ·ã¡ãŒã«äŸ
â ïž ãã㯠AI ãçæããåèäŸã§ããé
ä¿¡åã«å¿
ãå
容ãã確èªã®ããã貎瀟ã®ç¶æ³ã«åãããŠç·šéããŠãå©çšãã ãããå®éã®è¢«å®³ç¶æ³ãèªç€Ÿã®å©çšç°å¢ãèžãŸãã倿ã¯ã貎瀟ã®ã»ãã¥ãªãã£è²¬ä»»è
ã«ã確èªãã ããã
ä»¶å: ãæ³šæåèµ·ãäžå¯©ãªãã¡ã€ã«ã®éå°ã«é¢ãããæ³šæ
ãç²ãããŸã§ããæ å ±ã·ã¹ãã æ åœã§ãã
Windowsã®ç®¡çæ©èœïŒMMCïŒãæªçšããPCã®ç®¡çè æš©éãäžæ£ã«å¥ªåããæ»æã確èªãããŠããŸãã
ãååããé¡ããããããš:
1. éä¿¡å ãäžæãªã¡ãŒã«ã«æ·»ä»ãããŠãããã¡ã€ã«ããäžå¯©ãªãªã³ã¯ããããŠã³ããŒããããã¡ã€ã«ïŒç¹ã«æ¡åŒµåã .msc ã®ãã®ïŒã¯çµ¶å¯Ÿã«éããªãã§ãã ããã
2. Windows Updateã®éç¥ã衚瀺ãããŠããå Žåã¯ãéããã«æŽæ°ãé©çšããŠãã ããã
äžå¯©ãªæåã«æ°ã¥ããå Žåã¯ãããã«ã·ã¹ãã 管çè ãŸã§ãé£çµ¡ãã ããããæ©ãã®ã察å¿ããé¡ãããããŸãã
ãç²ãããŸã§ããæ å ±ã·ã¹ãã æ åœã§ãã
Windowsã®ç®¡çæ©èœïŒMMCïŒãæªçšããPCã®ç®¡çè æš©éãäžæ£ã«å¥ªåããæ»æã確èªãããŠããŸãã
ãååããé¡ããããããš:
1. éä¿¡å ãäžæãªã¡ãŒã«ã«æ·»ä»ãããŠãããã¡ã€ã«ããäžå¯©ãªãªã³ã¯ããããŠã³ããŒããããã¡ã€ã«ïŒç¹ã«æ¡åŒµåã .msc ã®ãã®ïŒã¯çµ¶å¯Ÿã«éããªãã§ãã ããã
2. Windows Updateã®éç¥ã衚瀺ãããŠããå Žåã¯ãéããã«æŽæ°ãé©çšããŠãã ããã
äžå¯©ãªæåã«æ°ã¥ããå Žåã¯ãããã«ã·ã¹ãã 管çè ãŸã§ãé£çµ¡ãã ããããæ©ãã®ã察å¿ããé¡ãããããŸãã
Subject: [Security Notice] Caution Regarding Suspicious Files
Hi everyone,
Our security team has identified a threat where attackers use malicious files to gain unauthorized administrator access to Windows computers.
How you can help:
1. Do not open attachments from unknown senders or files downloaded from untrusted sources, especially those with the .msc extension.
2. Please apply any pending Windows Updates as soon as they become available on your device.
If you notice any unusual activity on your computer, please report it to the IT helpdesk immediately. We appreciate your prompt cooperation.
Hi everyone,
Our security team has identified a threat where attackers use malicious files to gain unauthorized administrator access to Windows computers.
How you can help:
1. Do not open attachments from unknown senders or files downloaded from untrusted sources, especially those with the .msc extension.
2. Please apply any pending Windows Updates as soon as they become available on your device.
If you notice any unusual activity on your computer, please report it to the IT helpdesk immediately. We appreciate your prompt cooperation.
ä»¶å: ãè匱æ§å¯Ÿå¿ãMicrosoft MMCã«ãããç¹æš©ææ Œã®èåŒ±æ§ (CVE-2025-26633)
ãç²ãããŸã§ããæšèšã®è匱æ§ã«é¢ããæ å ±å ±æã§ãã
â æŠèŠ
Microsoft Management Console (MMC) ã®èåŒ±æ§ (CVE-2025-26633) ãå©çšããæªæã®ãã .msc ãã¡ã€ã«ãå®è¡ãããããšã§ãæ»æè ãããŒã«ã«ç®¡çè ã¢ã«ãŠã³ããä»»æã«äœæã§ããåé¡ã§ããCVSS 7.8 (High) ãšãããŠãããWater Gamayun APT çã®è åšã¢ã¯ã¿ãŒã«ããå®ç°å¢ã§ã®æªçšãå ±åãããŠããŸãã
â 圱é¿ç¯å²
- Windows 10 (å šãšãã£ã·ã§ã³)
- Windows 11 (å šãšãã£ã·ã§ã³)
- Windows Server 2016, 2019, 2022, 2025
â å¯Ÿå¿æé
1. 2025幎3æã® Microsoft ããã (KB5053602 以é) ãé©çšãããŠããã確èªããŠãã ããã
2. æªé©çšã®ç«¯æ«ã«å¯Ÿããåªå çã« Windows Update ã宿œããŠãã ããã
3. ãšã³ããã€ã³ãä¿è·è£œåã«ãŠãäžå¯©ãª .msc ãã¡ã€ã«ã®å®è¡ããäžèªç¶ãªããŒã«ã«ã¢ã«ãŠã³ãäœæã®ãã°ãç£èŠããŠãã ããã
â åèæ å ±
- CVE-2025-26633
- Exploit-DB EDB-ID: 52498
察å¿åªå 床: é«ïŒéãããªãããé©çšãæšå¥šïŒ
ãç²ãããŸã§ããæšèšã®è匱æ§ã«é¢ããæ å ±å ±æã§ãã
â æŠèŠ
Microsoft Management Console (MMC) ã®èåŒ±æ§ (CVE-2025-26633) ãå©çšããæªæã®ãã .msc ãã¡ã€ã«ãå®è¡ãããããšã§ãæ»æè ãããŒã«ã«ç®¡çè ã¢ã«ãŠã³ããä»»æã«äœæã§ããåé¡ã§ããCVSS 7.8 (High) ãšãããŠãããWater Gamayun APT çã®è åšã¢ã¯ã¿ãŒã«ããå®ç°å¢ã§ã®æªçšãå ±åãããŠããŸãã
â 圱é¿ç¯å²
- Windows 10 (å šãšãã£ã·ã§ã³)
- Windows 11 (å šãšãã£ã·ã§ã³)
- Windows Server 2016, 2019, 2022, 2025
â å¯Ÿå¿æé
1. 2025幎3æã® Microsoft ããã (KB5053602 以é) ãé©çšãããŠããã確èªããŠãã ããã
2. æªé©çšã®ç«¯æ«ã«å¯Ÿããåªå çã« Windows Update ã宿œããŠãã ããã
3. ãšã³ããã€ã³ãä¿è·è£œåã«ãŠãäžå¯©ãª .msc ãã¡ã€ã«ã®å®è¡ããäžèªç¶ãªããŒã«ã«ã¢ã«ãŠã³ãäœæã®ãã°ãç£èŠããŠãã ããã
â åèæ å ±
- CVE-2025-26633
- Exploit-DB EDB-ID: 52498
察å¿åªå 床: é«ïŒéãããªãããé©çšãæšå¥šïŒ
Subject: [Action Required] Local Privilege Escalation in Microsoft MMC (CVE-2025-26633)
Dear IT Administration Team,
We are sharing critical information regarding a vulnerability in the Microsoft Management Console (MMC).
â Overview
CVE-2025-26633 allows an attacker to create a local administrator account via a specially crafted .msc file. With a CVSS score of 7.8 (High), this vulnerability is being actively exploited in the wild by threat actors such as Water Gamayun APT.
â Affected Scope
- Windows 10 (All editions)
- Windows 11 (All editions)
- Windows Server 2016, 2019, 2022, 2025
â Mitigation Steps
1. Verify the installation of the March 2025 Microsoft security updates (KB5053602 or later).
2. Prioritize the deployment of these updates to all unpatched systems.
3. Monitor EDR/SIEM logs for the execution of suspicious .msc files or unauthorized local account creation.
â Reference
- CVE-2025-26633
- Exploit-DB EDB-ID: 52498
Priority: High (Prompt patching is strongly recommended)
Dear IT Administration Team,
We are sharing critical information regarding a vulnerability in the Microsoft Management Console (MMC).
â Overview
CVE-2025-26633 allows an attacker to create a local administrator account via a specially crafted .msc file. With a CVSS score of 7.8 (High), this vulnerability is being actively exploited in the wild by threat actors such as Water Gamayun APT.
â Affected Scope
- Windows 10 (All editions)
- Windows 11 (All editions)
- Windows Server 2016, 2019, 2022, 2025
â Mitigation Steps
1. Verify the installation of the March 2025 Microsoft security updates (KB5053602 or later).
2. Prioritize the deployment of these updates to all unpatched systems.
3. Monitor EDR/SIEM logs for the execution of suspicious .msc files or unauthorized local account creation.
â Reference
- CVE-2025-26633
- Exploit-DB EDB-ID: 52498
Priority: High (Prompt patching is strongly recommended)