CVE-2026-69331
massUse-After-Free Local Privilege Escalation in Windows Remote Access Connection Manager
CVE-2026-69331 is a use-after-free (CWE-416) vulnerability in the Windows Remote Access Connection Manager (RasMan), a built-in Windows service. An authorized attacker who already has valid low-privilege credentials on the local machine triggers the flaw through the remote access connection handling code, causing memory to be freed while still in use. Successful exploitation elevates the attacker's privileges locally, yielding high impact on confidentiality, integrity, and availability of the system. Any Windows installation running the RasMan service is potentially affected, per Microsoft's advisory (specific affected build ranges are not provided in the source data). There is currently no public proof-of-concept, no entry in CISA's KEV catalog, and a low 0.2% EPSS probability of exploitation in the next 30 days, indicating no known exploitation to date.
What to do: Apply the Windows security update for CVE-2026-69331 from Microsoft's advisory as soon as it is available for your Windows builds. Because exploitation requires local access with low privileges, prioritize patching multi-user systems, RDS/terminal hosts, and endpoints where untrusted users can log on locally. No public PoC or in-the-wild exploitation is known, so normal patch cadence is appropriate, but verify post-patch that RasMan is running the updated build.
| Microsoft Windows Remote Access Connection Manager (RasMan) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.