HIGH

CVE-2025-59230

Microsoft Windows 10 1507 2025-10-14 CVSS v3.1
CVSS
7.8
KEV

Description

Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

Summary dbcve.org

This is a local privilege escalation vulnerability in Windows Remote Access Connection Manager (RasMan). The improper access control vulnerability allows an authenticated local attacker to elevate their privileges by manipulating the service's access controls or associated resources to gain SYSTEM-level access.

Mitigation

Apply the Microsoft security update for CVE-2025-59230 through Windows Update or your patch management system, then verify the Remote Access Connection Manager service functions correctly.

Weakness (CWE)

CWE-284 Improper Access Control

EPSS Score

2.68%
Probability of exploitation in next 30 days
85.2th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE