Junglewise Threat Intelligence

CVE-2026-21525: Microsoft Windows NULL pointer dereference in Remote Access Connection Manager

CVE-2026-21525 · Severity: critical · CVSS 6.2 · Exploited in the wild · Published 2026-02-10

Technologies: Microsoft Windows 10, Microsoft Windows, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

Microsoft Windows Remote Access Connection Manager, which handles network connections, contains a flaw that can be used to crash the system. An attacker with local access to a computer can trigger this vulnerability to cause a blue screen or system restart, leading to a denial of service. This issue has been observed being used in active attacks, making prompt patching essential to maintain system stability.

Technical details

A NULL pointer dereference (CWE-476) exists in the Microsoft Windows Remote Access Connection Manager (rasman.dll). The vulnerability is triggered when the service improperly handles specific memory addresses, leading to a system crash (BSOD). The attack vector is local, requiring the attacker to execute code on the target system, though it does not require elevated privileges or user interaction. This vulnerability is listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild. Microsoft has released security updates to address this issue across supported versions of Windows and Windows Server.

Affected products

  • Microsoft Windows 10 Up to 10.0.19045.6937
  • Microsoft Windows 11 Up to 10.0.26200.7781
  • Microsoft Windows Server 2012 / 2016 / 2019 / 2022 / 2025 Various versions up to 10.0.26100.32313

Timeline

  • 2026-02-10: disclosed: Vulnerability disclosed by Microsoft
  • 2026-02-10: kev added: Added to CISA Known Exploited Vulnerabilities catalog
  • 2026-02-10: exploited: Confirmed active exploitation in the wild

Related threats