ZeroHour

CVE-2026-21525

KEVmass1

Local Denial-of-Service Flaw in Microsoft Windows Remote Access Connection Manager

CISA: Microsoft Windows NULL Pointer Dereference Vulnerability

CVSS 3.1
6.2 medium
EPSS
5%p92
Published
()
KEV added
AI analysis

CVE-2026-21525 is a null pointer dereference (CWE-476) in the Windows Remote Access Connection Manager (RasMan) component that can be triggered by an unauthorized attacker with local access to an affected machine, without valid credentials or user interaction. Triggering the flaw crashes the service or system, yielding a high-availability-impact denial of service with no confidentiality or integrity loss. Any organization running the affected Windows 10, Windows 11, or Windows Server builds is in scope, because the vulnerable component ships as part of the operating system. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-02-10, confirming active in-the-wild exploitation, and it was among the 59 fixes (including six actively exploited zero-days) in Microsoft's February 2026 Patch Tuesday. EPSS estimates a 5.0% probability of exploitation within 30 days (92nd percentile); no public proof-of-concept code is known.

What to do: Deploy the February 2026 Patch Tuesday Windows security updates to all affected Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2), and Windows Server 2012/2016/2019/2022/2022 23H2 systems; organizations bound by CISA BOD 22-01 must remediate within the required timeline or apply vendor mitigations. Because the attack vector is local and no public PoC or documented workaround exists, patching is the primary mitigation — prioritize multi-user servers, remote-access/VDI hosts, and shared endpoints, and confirm deployment through your patch-management reporting.

Affected
microsoft Windows 101607
microsoft Windows 101809
microsoft Windows 1021H2
microsoft Windows 1022H2
microsoft Windows 1123H2
microsoft Windows 1124H2
microsoft Windows 1125H2
microsoft Windows Server 20122012
microsoft Windows Server 20162016
microsoft Windows Server 20192019
microsoft Windows Server 20222022
microsoft Windows Server 20222022 23H2
Estimated exposure
masshundreds of millions of Windows client and server installations (affected builds span the supported Windows 10/11 and Windows Server installed base) — The affected versions cover nearly the entire supported Windows 10/11 client line and all supported Windows Server releases, which together run on well over a billion devices with the Remote Access Connection Manager service present by…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally.

CISA Known Exploited Vulnerability
Affected
Microsoft Windows
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows server 2012, windows server 2016, windows server 2019, windows server 2022, windows server 2022 23h2
Weakness
CWE-476
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news