HomeSecurityZero-day exploit in Windows Remote Access Connection Manager

Zero-day exploit in Windows Remote Access Connection Manager

Microsoft has confirmed the active exploitation of a serious zero-day vulnerability in the Windows Remote Access Connection Manager (RasMan) service . The vulnerability allows attackers to escalate privileges and potentially compromise entire systems.

 zero-day Windows Remote Access Connection Manager

The vulnerability, tracked as CVE-2025-59230, results from improper access control, allowing low-privileged users to gain SYSTEM. It was discovered on October 14, 2025, and affects multiple versions of Windows, having already attracted the attention of malicious actors targeting corporate environments.

See also: Vulnerability in Elastic Cloud Enterprise allows execution of malicious commands

Windows Remote Access Connection Manager: Vulnerability Affects Multiple Versions

The issue is located in RasMan, a key component that manages remote access connections such as VPNs and dial-up. A privileged local attacker could exploit weak permission checks to modify the service's settings, bypassing normal privilege limits.

Zero-day exploit in Windows Remote Access Connection Manager

With a CVSS v3.1 baseline score of 7.8 (High Severity), it requires only local access and low privileges, making it a prime target for privilege escalation after a breach. Microsoft classifies it as “Exploitation Detected,” indicating real-world attacks, though details remain unknown.

See also: New PoC Exploit for Sudo Chroot Privilege Escalation Vulnerability

No public proof-of-concept (PoC) exploit has been released, but security researchers describe possible exploits that involve registry manipulation or DLL injection into RasMan processes. For example, an attacker could use low-integrity processes to overwrite accessible files in the RasMan directory (e.g., C:\Windows\System32\ras), injecting malicious code that runs with elevated privileges when the service restarts. This can be combined with initial accesses from phishing or unpatched applications, increasing the damage in lateral movement scenarios.

See also: Ivanti: Warns of 13 vulnerabilities in Endpoint Manager (EPM)

Zero-day exploit in Windows Remote Access Connection Manager

Affected systems include Windows 10 (version 1809 and later), Windows 11, and Windows Server 2019-2025. Microsoft recommends updating immediately via the October 2025 Patch Tuesday, stressing that unupdated machines are at high risk from government actors or ransomware groups.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS