CVE-2026-71352
8.8Microsoft · Windows
An integer underflow vulnerability in the Windows Remote Access Connection Manager allows an authenticated attacker to execute arbitrary code over a network.
Executive summary
A critical integer underflow vulnerability in the Windows Remote Access Connection Manager allows authenticated attackers to achieve remote code execution.
Vulnerability
This flaw is an integer underflow (CWE-191) residing in the Windows Remote Access Connection Manager. It requires the attacker to hold authenticated access (PR:L) to the system, at which point they can trigger the vulnerability over the network to execute arbitrary code.
Business impact
The vulnerability carries a CVSS score of 8.8, indicating a high level of risk to organizational infrastructure. Successful exploitation allows an attacker to gain full control over the affected system, potentially leading to total system compromise, unauthorized access to sensitive data, and significant operational disruption.
Remediation
Immediate Action: Apply the security updates provided by Microsoft in the September 2026 patch cycle corresponding to the specific build numbers listed in the enrichment data.
Proactive Monitoring: Monitor network traffic and system access logs for anomalous activity originating from authenticated user accounts, specifically focusing on the Remote Access Connection Manager service.
Compensating Controls: Ensure that access to remote management services is restricted to authorized personnel only, utilizing network segmentation and strict Identity and Access Management policies to reduce the attack surface.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the high CVSS score and the potential for remote code execution, organizations should prioritize patching all affected Windows workstations and servers. Administrators must verify their build versions against the provided list and deploy the relevant Microsoft security updates immediately to mitigate the risk of unauthorized system takeover.
More Microsoft CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section