CVE-2026-69455
massHeap Overflow in Windows Remote Access Connection Manager Enables Privilege Escalation
CVE-2026-69455 is a heap-based buffer overflow (CWE-122) in the Windows Remote Access Connection Manager (RasMan), the built-in Windows service that manages remote access connections such as VPN and dial-up. The flaw is triggered by an authorized attacker who already has local access and can make the service mishandle heap memory; Microsoft has not publicly detailed the exact trigger path and no public proof-of-concept is known. A successful exploit allows a low-privileged local user to elevate privileges on the host, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8, local attack vector, low privileges required). Any Windows system shipping the affected component is potentially impacted, but the available data does not specify which Windows releases or builds are in scope, so Microsoft's advisory governs the affected range. There is currently no evidence of exploitation: the flaw is not in CISA's KEV, EPSS estimates a 0.3% probability of exploitation within 30 days (25th percentile), and no public PoC exists.
What to do: Because the available data lists no patched builds or KB numbers, monitor Microsoft's Security Update Guide entry for CVE-2026-69455 and apply the corresponding Windows update as soon as it is published, prioritizing hosts where untrusted users can execute code locally. In the meantime, inventory which endpoints run the Remote Access Connection Manager (RasMan/RemoteAccess) service and disable it where remote access (VPN/dial-up) functionality is unused to reduce exposure, and watch KEV/EPSS for signs of emerging exploitation.
| Microsoft Windows Remote Access Connection Manager (RasMan) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-122
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.