Junglewise Threat Intelligence

CVE-2026-71342: Microsoft Windows Remote Access Connection Manager use-after-free privilege escalation

CVE-2026-71342 · Severity: high · CVSS 7 · Published 2026-09-08

Executive brief

Windows Remote Access Connection Manager is a system component that manages remote connectivity on Windows servers and client systems. A use-after-free memory vulnerability in this component allows an authorized local attacker to escalate their privileges on the affected system, potentially gaining administrative access and full system control.

Technical details

A use-after-free vulnerability exists in Windows Remote Access Connection Manager where freed memory is accessed after deallocation, leading to memory corruption. The vulnerability requires the attacker to already possess local access and valid credentials on the system. By crafting a malicious request through the Remote Access Connection Manager, an authenticated attacker can trigger the use-after-free condition and achieve privilege escalation from a standard user to SYSTEM or Administrator privileges. The vulnerability is exploitable via local attack vector only, and Microsoft has released security patches to remediate the issue.

Affected products

  • Microsoft Windows Remote Access Connection Manager <UNKNOWN>

Timeline

  • 2026-09-08: disclosed: CVE-2026-71342 published

References

Related threats