CVE-2025-59230
9.5 CISA KEVMicrosoft · Windows
An improper access control vulnerability in the Windows Remote Access Connection Manager allows an authenticated attacker to perform local privilege escalation.
Executive summary
A critical privilege escalation vulnerability in Microsoft Windows is currently being exploited in the wild, posing a severe risk to system integrity and security.
Vulnerability
This flaw involves improper access control within the Windows Remote Access Connection Manager. An attacker who has already gained low-level access to the system can exploit this weakness to escalate their privileges to a higher level.
Business impact
The ability for a low-privileged user to escalate to administrative privileges presents a critical risk, as it allows for complete system compromise. With a CVSS score of 9.5, this vulnerability could lead to unauthorized data exfiltration, the deployment of malicious software, or total system disruption. Such an event would likely result in significant reputational damage and operational downtime for the organization.
Remediation
Immediate Action: Apply the relevant security updates provided by Microsoft in the official update guide as a matter of extreme urgency.
Proactive Monitoring: Monitor system logs for unusual process execution patterns or unexpected changes to user group memberships, particularly those involving the Remote Access Connection Manager.
Compensating Controls: Ensure that the principle of least privilege is strictly enforced across all user accounts to minimize the potential impact of an initial system compromise.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Due to the confirmed active exploitation of this vulnerability in the wild, organizations must prioritize patching all affected Windows systems immediately. The potential for total system compromise makes this a critical security event that requires immediate attention from IT and security operations teams to prevent unauthorized escalation and potential data loss.
More Microsoft CVEs all →
History
- Disclosed CVE record published
- Published in the daily brief high section
- Published in the daily brief high section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief critical section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Analyst report written
- Fix documented version 10.0.10240.21161 per CVE record