ZeroHour

CVE-2026-71333

mass

Use-after-free local privilege escalation in Windows Remote Access Connection Manager

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-71333 is a use-after-free memory-safety flaw (CWE-416) in the Windows Remote Access Connection Manager (RasMan), the built-in Windows service that handles remote access and VPN connection management. An attacker who already has a low-privileged, authenticated foothold on a machine can trigger the condition by causing the service to use memory that has already been freed; the high attack complexity (AC:H) indicates specific timing or state conditions are required, and no user interaction is needed. Successful exploitation lets the attacker elevate privileges locally, gaining high-impact control over the confidentiality, integrity, and availability of the host. Any Windows system running the affected RasMan component is potentially exposed, though the provided data does not specify which Windows versions are in scope. There is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns only a ~0.3% chance of exploitation in the next 30 days, indicating no confirmed exploitation activity.

What to do: Install the fix for CVE-2026-71333 from Microsoft's advisory via Windows Update as soon as it is published, prioritizing multi-user and untrusted-local-user hosts such as RDS servers, shared workstations, and kiosks. As an interim mitigation, consider disabling the Remote Access Connection Manager (RasMan) service on systems that do not use VPN or dial-up/remote access functionality, after confirming nothing depends on it. No public exploit exists, so mass-scan for indicators is not warranted, but monitor EPSS and the CISA KEV catalog for status changes.

Affected
Microsoft Windows (Remote Access Connection Manager / RasMan service)
Estimated exposure
mass≈1 billion+ Windows endpoints (built-in RasMan service present on standard Windows installs) — Windows is publicly estimated to run on more than a billion active devices and the RasMan service ships with standard Windows installations, so the theoretical exposure base is on the order of a billion machines, though only hosts with…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.