Junglewise Threat Intelligence

CVE-2025-59230: Microsoft Windows privilege escalation in Remote Access Connection Manager

CVE-2025-59230 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2025-10-14

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

A vulnerability exists in the Windows Remote Access Connection Manager, a component that handles network connections to remote computers. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This vulnerability is known to be actively exploited in the wild, making it a high priority for remediation.

Technical details

An improper access control vulnerability (CWE-284) exists in the Windows Remote Access Connection Manager (RasMan) service. The flaw allows a locally authenticated attacker with low privileges to bypass security restrictions and elevate their permissions to a higher level, potentially SYSTEM. The attack vector is local, requiring the attacker to already have execution capabilities on the target host. This vulnerability has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation. Microsoft has released security updates to address this issue across supported versions of Windows and Windows Server.

Affected products

  • Microsoft Windows Windows 10, Windows 11, Windows Server 2008, 2012, 2016, 2019, 2022, 2025

Timeline

  • 2025-10-14: disclosed
  • 2025-10-14: advisory
  • 2025-10-14: kev added: Added to CISA KEV catalog
  • 2025-10-14: exploited

Related threats