Hackers Exploit Windows Remote Access Connection Manager 0-Day in Ongoing Attacks
Microsoft has confirmed the active exploitation of a critical zero-day vulnerability in the Windows Remote Access Connection Manager, identified as CVE-2025-59230.
Microsoft has confirmed the active exploitation of a critical zero-day vulnerability in the Windows Remote Access Connection Manager, identified as CVE-2025-59230.
Zero-Day Vulnerability Enables System-Level Access
This vulnerability arises from improper access control within the Windows Remote Access Connection Manager, a vital service for handling remote network connections in Windows operating systems.
Attribute Details
CVE ID CVE-2025-59230
Vulnerability Type Elevation of Privilege
Release Date October 14, 2025
The vulnerability has a CVSS base score of 7.8 and a temporal score of 7.2, and is rated as "Important" by Microsoft.
CVSS Score 7.8 (Base) / 7.2 (Temporal)
Severity Important
Security researchers at Microsoft Threat Intelligence Center and Microsoft Security Response Center discovered evidence of active exploitation in the wild before a patch became available, classifying it as a true zero-day threat.
The vulnerability has a CVSS base score of 7.8 and a temporal score of 7.2, and is rated as "Important" by Microsoft.
The attack requires local access to the target system, meaning the attacker must have a foothold on the machine with low-level user privileges. However, the low attack complexity allows straightforward exploitation with no user interaction needed.
The vulnerability allows potential privilege escalation to SYSTEM level, granting attackers unrestricted access to read, modify, or delete data, install malicious software, create new administrator accounts, and maintain persistent access.
Microsoft confirms that functional exploit code exists and has been detected in real-world attacks. Although the vulnerability was not publicly disclosed prior to Microsoft's announcement, it is being actively leveraged by threat actors.
Organizations are urged to apply security updates immediately. The Windows Remote Access Connection Manager is present across multiple Windows versions, potentially exposing many systems to compromise.
Security experts recommend prioritizing patching efforts, especially for systems accessible to multiple users or those connected to corporate networks. It is also advised to monitor for suspicious privilege escalation attempts and review system logs for indicators of compromise related to the Remote Access Connection Manager service.
Based on reporting by GBHackers.
