ZeroHour

CVE-2026-69455

mass

Heap Overflow in Windows Remote Access Connection Manager Enables Privilege Escalation

CVSS 3.1
7.8 high
EPSS
<1%p25
Published
()
Modified
AI analysis

CVE-2026-69455 is a heap-based buffer overflow (CWE-122) in the Windows Remote Access Connection Manager (RasMan), the built-in Windows service that manages remote access connections such as VPN and dial-up. The flaw is triggered by an authorized attacker who already has local access and can make the service mishandle heap memory; Microsoft has not publicly detailed the exact trigger path and no public proof-of-concept is known. A successful exploit allows a low-privileged local user to elevate privileges on the host, with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8, local attack vector, low privileges required). Any Windows system shipping the affected component is potentially impacted, but the available data does not specify which Windows releases or builds are in scope, so Microsoft's advisory governs the affected range. There is currently no evidence of exploitation: the flaw is not in CISA's KEV, EPSS estimates a 0.3% probability of exploitation within 30 days (25th percentile), and no public PoC exists.

What to do: Because the available data lists no patched builds or KB numbers, monitor Microsoft's Security Update Guide entry for CVE-2026-69455 and apply the corresponding Windows update as soon as it is published, prioritizing hosts where untrusted users can execute code locally. In the meantime, inventory which endpoints run the Remote Access Connection Manager (RasMan/RemoteAccess) service and disable it where remote access (VPN/dial-up) functionality is unused to reduce exposure, and watch KEV/EPSS for signs of emerging exploitation.

Affected
Microsoft Windows Remote Access Connection Manager (RasMan)
Estimated exposure
mass>1 billion Windows endpoints (RasMan is a built-in Windows service, so the component ships with essentially the entire Windows fleet) — RasMan ships as a built-in component across Windows client and server installations and Microsoft has publicly cited more than 1 billion active Windows devices, making the installed base on the order of a billion endpoints, though actual…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.