CVE-2026-71333
massUse-after-free local privilege escalation in Windows Remote Access Connection Manager
CVE-2026-71333 is a use-after-free memory-safety flaw (CWE-416) in the Windows Remote Access Connection Manager (RasMan), the built-in Windows service that handles remote access and VPN connection management. An attacker who already has a low-privileged, authenticated foothold on a machine can trigger the condition by causing the service to use memory that has already been freed; the high attack complexity (AC:H) indicates specific timing or state conditions are required, and no user interaction is needed. Successful exploitation lets the attacker elevate privileges locally, gaining high-impact control over the confidentiality, integrity, and availability of the host. Any Windows system running the affected RasMan component is potentially exposed, though the provided data does not specify which Windows versions are in scope. There is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns only a ~0.3% chance of exploitation in the next 30 days, indicating no confirmed exploitation activity.
What to do: Install the fix for CVE-2026-71333 from Microsoft's advisory via Windows Update as soon as it is published, prioritizing multi-user and untrusted-local-user hosts such as RDS servers, shared workstations, and kiosks. As an interim mitigation, consider disabling the Remote Access Connection Manager (RasMan) service on systems that do not use VPN or dial-up/remote access functionality, after confirming nothing depends on it. No public exploit exists, so mass-scan for indicators is not warranted, but monitor EPSS and the CISA KEV catalog for status changes.
| Microsoft Windows (Remote Access Connection Manager / RasMan service) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.