Executive brief
Windows Remote Access Connection Manager is a system component that manages remote network connections on Windows systems. An integer underflow vulnerability in this component allows an authenticated network attacker to execute arbitrary code with elevated privileges, potentially compromising the entire system.
Technical details
An integer underflow (wraparound) vulnerability exists in Windows Remote Access Connection Manager that can be exploited by an authorized/authenticated attacker over the network. The vulnerability permits arbitrary code execution, suggesting a memory corruption or buffer overflow condition triggered by crafted input. Exploitation requires network access and prior authentication. A patch from Microsoft is expected; consult the Microsoft Security Response Center for available updates.
Affected products
- Microsoft Windows Remote Access Connection Manager
Timeline
- 2026-09-08: disclosed