This is a critical security issue affecting Windows Remote Access Connection Manager (RasMan) that allows local attackers to execute arbitrary code with SYSTEM privileges.
See also: Microsoft finally has a prettier Run dialog for Windows 11

While investigating CVE-2025-59230 , the vulnerability that Microsoft addressed with the October 2025 security updates , 0patch security analysts identified a complex exploit chain that relies on a secondary, previously unknown zero-day vulnerability to function effectively.
The main vulnerability, CVE-2025-59230, is related to the way the RasMan handles RPC endpoints. When it starts, the service registers a specific endpoint, which is considered trusted by other services with elevated privileges.
0patch researchers found that if RasMan is not running, an attacker can register the endpoint first. When privileged services attempt to connect, they unknowingly communicate with the attacker's process, which allows malicious commands to be executed.
See also: Microsoft silently fixes Windows LNK error

However, exploiting this race condition is difficult, as RasMan usually starts automatically at system startup, leaving little to no room for the attacker to register the endpoint first.
To circumvent this limitation, the discovered exploit exploits a second, unpatched vulnerability. This zero-day vulnerability allows an unprivileged user to intentionally crash the RasMan service. 0patch has released micropatches that address this crash scenario on all supported platforms, including Windows 11 and Windows Server 2025.
See also: KimJongRAT targets Windows users via infected .hta files

System administrators are advised to immediately install the October 2025 Windows security updatesto mitigate the underlying privilege escalation.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
