Windows Remote Access Connection Manager 0-Day Vulnerability Actively Exploited in Attacks
Microsoft has identified active exploitation of a critical zero-day vulnerability in the Windows Remote Access Connection Manager (RasMan) service. This vulnerability allows attackers to escalate privileges and potentially compromise entire systems.
Microsoft has identified active exploitation of a critical zero-day vulnerability in the Windows Remote Access Connection Manager (RasMan) service. This vulnerability allows attackers to escalate privileges and potentially compromise entire systems.
The vulnerability, designated as CVE-2025-59230 , arises from improper access control mechanisms. It enables low-privileged users to gain SYSTEM-level access.
Disclosed on October 14, 2025, this flaw affects multiple Windows versions and has already been targeted by threat actors in enterprise environments.
The issue is located within RasMan, a core component responsible for handling remote access connections, such as VPNs and dial-up. An authorized local attacker can exploit weak permission checks in the service configurations, bypassing standard privilege boundaries.
The vulnerability has a CVSS v3.1 base score of 7.8, categorized as high severity. It requires only local access and low privileges, making it a prime target for post-compromise escalation.
Microsoft has labeled the vulnerability as "Exploitation Detected," indicating real-world attack occurrences. However, detailed information about the affected victims remains undisclosed.
Below is a summary of key CVE-2025-59230 metrics:
Microsoft has identified active exploitation of a critical zero-day vulnerability in the Windows Remote Access Connection Manager (RasMan) service.
Metric Value Description
CVSS v3.1 Base Score 7.8 (High) Overall severity rating
Attack Vector Local (AV:L) Requires physical or logged-in access
Attack Complexity Low (AC:L) Straightforward exploitation
Privileges Required Low (PR:L) Basic user account suffices
User Interaction None (UI:N) No victim engagement needed
Confidentiality/Integrity/Availability Impact High (C:H/I:H/A:H) Full system compromise possible
Exploit Maturity Functional (E:F) Proof-of-exploits exist
Affected systems include Windows 10 (versions 1809 and later), Windows 11, and Windows Server 2019-2025. Microsoft advises immediate patching through the October 2025 Patch Tuesday updates , emphasizing that unpatched systems are highly vulnerable to nation-state actors or ransomware groups.
Based on reporting by Cyber Security News.
