Microsoft has confirmed the active exploitation of a serious zero-day vulnerability in the Windows Remote Access Connection Manager (RasMan) service . The vulnerability allows attackers to escalate privileges and potentially compromise entire systems.

The vulnerability, tracked as CVE-2025-59230, results from improper access control, allowing low-privileged users to gain SYSTEM. It was discovered on October 14, 2025, and affects multiple versions of Windows, having already attracted the attention of malicious actors targeting corporate environments.
See also: Vulnerability in Elastic Cloud Enterprise allows execution of malicious commands
Windows Remote Access Connection Manager: Vulnerability Affects Multiple Versions
The issue is located in RasMan, a key component that manages remote access connections such as VPNs and dial-up. A privileged local attacker could exploit weak permission checks to modify the service's settings, bypassing normal privilege limits.

With a CVSS v3.1 baseline score of 7.8 (High Severity), it requires only local access and low privileges, making it a prime target for privilege escalation after a breach. Microsoft classifies it as “Exploitation Detected,” indicating real-world attacks, though details remain unknown.
See also: New PoC Exploit for Sudo Chroot Privilege Escalation Vulnerability
No public proof-of-concept (PoC) exploit has been released, but security researchers describe possible exploits that involve registry manipulation or DLL injection into RasMan processes. For example, an attacker could use low-integrity processes to overwrite accessible files in the RasMan directory (e.g., C:\Windows\System32\ras), injecting malicious code that runs with elevated privileges when the service restarts. This can be combined with initial accesses from phishing or unpatched applications, increasing the damage in lateral movement scenarios.
See also: Ivanti: Warns of 13 vulnerabilities in Endpoint Manager (EPM)

Affected systems include Windows 10 (version 1809 and later), Windows 11, and Windows Server 2019-2025. Microsoft recommends updating immediately via the October 2025 Patch Tuesday, stressing that unupdated machines are at high risk from government actors or ransomware groups.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
