CVE-2026-21525

9.5 CISA KEV

Microsoft · Windows

A null pointer dereference in the Windows Remote Access Connection Manager (RASMAN) service allows an unauthenticated local attacker to trigger a denial of service condition.

Executive summary

This critical vulnerability in the Windows Remote Access Connection Manager is currently being exploited in the wild, posing an immediate risk of service disruption.

Vulnerability

The vulnerability is a null pointer dereference (CWE-476) occurring within the Remote Access Connection Manager (RASMAN) service. An unauthenticated local attacker can trigger this flaw to cause a system denial of service.

Business impact

Successful exploitation results in a denial of service, rendering the affected Windows system unresponsive or causing it to crash. With a CVSS score of 9.5, this vulnerability represents a severe threat to operational availability, particularly in environments where system uptime is critical. Given that the flaw is actively exploited in the wild, the risk of unplanned downtime and business disruption is extremely high.

Remediation

Immediate Action: Apply the February 2026 cumulative security updates provided by Microsoft to all affected systems immediately.

Proactive Monitoring: Monitor system event logs for crashes related to the RASMAN service or unexpected reboots that may indicate exploitation attempts.

Compensating Controls: Ensure that access to local workstations and servers is restricted to authorized personnel only to limit the attack surface for local exploitation vectors.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Due to the confirmed active exploitation of this vulnerability and its potential to cause widespread service disruption, immediate patching is required. Organizations should prioritize the deployment of the February 2026 cumulative updates across all identified Windows platforms to neutralize this critical threat. Failure to remediate this issue promptly leaves systems vulnerable to disruption by local attackers.

More Microsoft CVEs

Sources