Executive brief
Windows Remote Access Connection Manager is a system component that manages remote connectivity to Windows machines. A missing authorization check allows an authenticated local user to modify remote access settings or configurations they should not have access to, potentially compromising system integrity or enabling further attacks.
Technical details
This vulnerability is a missing authorization (CWE-862) issue in Windows Remote Access Connection Manager. An authenticated local attacker can bypass authorization controls and tamper with remote access configurations or settings. The attack vector is local and requires prior authentication; the attacker cannot escalate privileges or gain remote access through this flaw alone, but can modify system state in ways that violate security policy. A patch has been published by Microsoft.
Affected products
- Microsoft Windows Remote Access Connection Manager
Timeline
- 2026-09-08: disclosed
- 2026-09-08: patched