CVE-2025-59230
KEVmassLocal Privilege Escalation in Windows Remote Access Connection Manager (RasMan)
CISA: Microsoft Windows Improper Access Control Vulnerability
CVE-2025-59230 is an improper access control flaw (CWE-284) in the Windows Remote Access Connection Manager service that allows an attacker who already has low-privileged access on a machine to gain elevated privileges locally. It is triggered by a local, authenticated user abusing the flawed access checks in the service; no remote or unauthenticated attack path is indicated by the CVSS vector (AV:L/PR:L). A successful exploit yields high impact to confidentiality, integrity and availability on the host, effectively giving the attacker full local control that can support persistence and lateral movement. All listed Windows 10 and Windows 11 releases and Windows Server 2008, 2012 and 2016 are affected. The flaw is being actively exploited: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-10-14, coinciding with Microsoft's October 2025 Patch Tuesday (one of six actively exploited zero-days patched that day), though no public PoC is known and ransomware use is unknown.
What to do: Apply Microsoft's October 2025 security updates for the affected Windows 10/11 and Windows Server releases immediately, prioritizing the per-version updates listed in Microsoft's advisory; as a CISA KEV entry (added 2025-10-14), BOD 22-01 remediation timelines apply for federal agencies. Because exploitation requires local code execution, prioritize hosts where low-privileged users can run code (RDS/VDI servers, kiosks, shared workstations) and verify that clients and servers have pulled the latest cumulative updates rather than relying on HEU state. There is no public PoC or documented mitigation, so patching is the primary defense.
| microsoft Windows 10 | 1507, 1607, 1809, 21H2, 22H2 |
| microsoft Windows 11 | 22H2, 23H2, 24H2, 25H2 |
| microsoft Windows Server | 2008, 2012, 2016 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
- Affected
- Microsoft Windows
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- microsoft
- Products
- windows 10 1507, windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows server 2008, windows server 2012, windows server 2016
- Weakness
- CWE-284
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H