HIGH
CVE-2025-59230
CVSS
7.8
KEV
Description
Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
Summary dbcve.org
This is a local privilege escalation vulnerability in Windows Remote Access Connection Manager (RasMan). The improper access control vulnerability allows an authenticated local attacker to elevate their privileges by manipulating the service's access controls or associated resources to gain SYSTEM-level access.
Mitigation
Apply the Microsoft security update for CVE-2025-59230 through Windows Update or your patch management system, then verify the Remote Access Connection Manager service functions correctly.
Weakness (CWE)
CWE-284
Improper Access Control
EPSS Score
2.68%
Probability of exploitation in next 30 days
85.2th percentile
References
https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59230
Vendor Advisory
https://www.vicarius.io/vsociety/posts/cve-2025-59230-detection-script-elevation-of-privilege-vulnerability-affecting-windows-rasman
Third Party Advisory
https://www.vicarius.io/vsociety/posts/cve-2025-59230-mitigation-script-elevation-of-privilege-vulnerability-affecting-windows-rasman
Mitigation, Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-59230
US Government Resource
Base CVE data derived from NVD (public domain). Enrichment by
dbcve.org
(CC-BY-4.0). Fetched via API.