Junglewise Threat Intelligence

CVE-2026-69455: Microsoft Windows Remote Access Connection Manager heap overflow

CVE-2026-69455 · Severity: high · CVSS 7.8 · Published 2026-09-08

Technologies: Microsoft Windows. Vendors: Microsoft.

Executive brief

Windows Remote Access Connection Manager contains a heap buffer overflow vulnerability that allows an authorized local attacker to elevate privileges on the system. This could enable an attacker with limited account access to gain administrative control of a Windows machine, potentially compromising all data and systems on that device.

Technical details

A heap-based buffer overflow exists in the Windows Remote Access Connection Manager, exploitable by an authenticated local attacker to achieve privilege escalation. The vulnerability requires local access and prior authentication; an attacker can trigger the overflow to overwrite heap memory and execute arbitrary code with elevated privileges.

Affected products

  • Microsoft Windows

Timeline

  • 2026-09-08: disclosed

References

Related threats