ZeroHour

CVE-2026-69331

mass

Use-After-Free Local Privilege Escalation in Windows Remote Access Connection Manager

CVSS 3.1
7.0 high
EPSS
<1%p10
Published
()
Modified
AI analysis

CVE-2026-69331 is a use-after-free (CWE-416) vulnerability in the Windows Remote Access Connection Manager (RasMan), a built-in Windows service. An authorized attacker who already has valid low-privilege credentials on the local machine triggers the flaw through the remote access connection handling code, causing memory to be freed while still in use. Successful exploitation elevates the attacker's privileges locally, yielding high impact on confidentiality, integrity, and availability of the system. Any Windows installation running the RasMan service is potentially affected, per Microsoft's advisory (specific affected build ranges are not provided in the source data). There is currently no public proof-of-concept, no entry in CISA's KEV catalog, and a low 0.2% EPSS probability of exploitation in the next 30 days, indicating no known exploitation to date.

What to do: Apply the Windows security update for CVE-2026-69331 from Microsoft's advisory as soon as it is available for your Windows builds. Because exploitation requires local access with low privileges, prioritize patching multi-user systems, RDS/terminal hosts, and endpoints where untrusted users can log on locally. No public PoC or in-the-wild exploitation is known, so normal patch cadence is appropriate, but verify post-patch that RasMan is running the updated build.

Affected
Microsoft Windows Remote Access Connection Manager (RasMan)
Estimated exposure
masshundreds of millions of Windows installations (RasMan ships with Windows) — The Remote Access Connection Manager is a built-in Windows component present on effectively all Windows client and server installations, so the affected population roughly tracks the overall Windows install base (on the order of a billion…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.