Junglewise Threat Intelligence

CVE-2026-71343: Microsoft Windows Remote Access Connection Manager heap buffer overflow

CVE-2026-71343 · Severity: high · CVSS 7.8 · Published 2026-09-08

Executive brief

Windows Remote Access Connection Manager is a system component that manages remote access connections on Windows computers. A heap buffer overflow in this component allows an authorized local user to execute arbitrary code with elevated privileges, potentially compromising the entire system.

Technical details

The vulnerability is a heap-based buffer overflow in the Windows Remote Access Connection Manager component. An authenticated local attacker can exploit this memory corruption flaw to execute arbitrary code with system-level privileges. The vulnerability requires local access and authentication; remote exploitation is not possible. Successful exploitation allows full system compromise. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows Remote Access Connection Manager

Timeline

  • 2026-09-08: disclosed

References

Related threats