Executive brief
Windows Remote Access Connection Manager contains a heap buffer overflow vulnerability that allows an authorized local attacker to elevate privileges on the system. This could enable an attacker with limited account access to gain administrative control of a Windows machine, potentially compromising all data and systems on that device.
Technical details
A heap-based buffer overflow exists in the Windows Remote Access Connection Manager, exploitable by an authenticated local attacker to achieve privilege escalation. The vulnerability requires local access and prior authentication; an attacker can trigger the overflow to overwrite heap memory and execute arbitrary code with elevated privileges.
Affected products
- Microsoft Windows
Timeline
- 2026-09-08: disclosed