CVE-2025-59230

9.5 CISA KEV

Microsoft · Windows

An improper access control vulnerability in the Windows Remote Access Connection Manager allows an authenticated attacker to perform local privilege escalation.

Executive summary

A critical privilege escalation vulnerability in Microsoft Windows is currently being exploited in the wild, posing a severe risk to system integrity and security.

Vulnerability

This flaw involves improper access control within the Windows Remote Access Connection Manager. An attacker who has already gained low-level access to the system can exploit this weakness to escalate their privileges to a higher level.

Business impact

The ability for a low-privileged user to escalate to administrative privileges presents a critical risk, as it allows for complete system compromise. With a CVSS score of 9.5, this vulnerability could lead to unauthorized data exfiltration, the deployment of malicious software, or total system disruption. Such an event would likely result in significant reputational damage and operational downtime for the organization.

Remediation

Immediate Action: Apply the relevant security updates provided by Microsoft in the official update guide as a matter of extreme urgency.

Proactive Monitoring: Monitor system logs for unusual process execution patterns or unexpected changes to user group memberships, particularly those involving the Remote Access Connection Manager.

Compensating Controls: Ensure that the principle of least privilege is strictly enforced across all user accounts to minimize the potential impact of an initial system compromise.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Due to the confirmed active exploitation of this vulnerability in the wild, organizations must prioritize patching all affected Windows systems immediately. The potential for total system compromise makes this a critical security event that requires immediate attention from IT and security operations teams to prevent unauthorized escalation and potential data loss.

More Microsoft CVEs all →

History

  1. Disclosed CVE record published
  2. Published in the daily brief high section
  3. Published in the daily brief high section
  4. Published in the daily brief kev section
  5. Published in the daily brief kev section
  6. Published in the daily brief kev section
  7. Published in the daily brief critical section
  8. Published in the daily brief kev section
  9. Published in the daily brief kev section
  10. Published in the daily brief kev section
  11. Published in the daily brief kev section
  12. Published in the daily brief kev section
  13. Published in the daily brief kev section
  14. Published in the daily brief kev section
  15. Published in the daily brief kev section
  16. Published in the daily brief kev section
  17. Published in the daily brief kev section
  18. Published in the daily brief kev section
  19. Published in the daily brief kev section
  20. Published in the daily brief kev section
  21. Published in the daily brief kev section
  22. Published in the daily brief kev section
  23. Analyst report written
  24. Fix documented version 10.0.10240.21161 per CVE record

Sources