Executive brief
Windows Remote Access Connection Manager is a system component that manages remote access connections on Windows systems. A use-after-free memory vulnerability allows an authorized local user to execute arbitrary code with elevated privileges, potentially compromising the entire system.
Technical details
A use-after-free vulnerability exists in Windows Remote Access Connection Manager where freed memory is accessed after deallocation. This memory safety issue can be exploited by an authenticated local attacker to corrupt memory and execute arbitrary code with elevated privileges. The vulnerability requires local access and prior authentication to the system. Microsoft has issued security patches to address this issue.
Affected products
- Microsoft Windows
Timeline
- 2026-09-08: disclosed