MEDIUM

CVE-2026-21525

Microsoft Windows 10 1607 2026-02-10 CVSS v3.1
CVSS
6.2
KEV

Description

Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally.

Summary dbcve.org

A null pointer dereference vulnerability exists in Windows Remote Access Connection Manager that allows a local unauthenticated attacker to cause a denial of service by triggering the service to dereference a null pointer, resulting in a crash.

Mitigation

Apply vendor-supplied Windows security patches for the Remote Access Connection Manager component to address the null pointer dereference vulnerability.

Weakness (CWE)

CWE-476 NULL Pointer Dereference

EPSS Score

5.04%
Probability of exploitation in next 30 days
91.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE