CVE-2026-71342
massUse-After-Free LPE in Microsoft Windows Remote Access Connection Manager
CVE-2026-71342 is a use-after-free memory-safety flaw (CWE-416) in the Windows Remote Access Connection Manager (RasMan) service. An attacker who already holds valid, low-privileged credentials on the machine can trigger the bug; the high attack-complexity score (AC:H) indicates exploitation depends on less-repeatable conditions such as specific service state or timing. Successful exploitation lets the attacker elevate privileges and fully compromise the local system, with high impact on confidentiality, integrity, and availability. Affected scope is Windows editions carrying the Remote Access Connection Manager component; the available data does not enumerate specific affected versions or builds, so defenders should check Microsoft's advisory for the exact affected range. There are no reports of in-the-wild exploitation, no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days.
What to do: Apply the Windows security update for CVE-2026-71342 published in Microsoft's security advisory via Windows Update/WSUS as it becomes available, and prioritize multi-user systems (RDP/terminal servers, VDI, shared workstations) where standard users can sign in interactively. Since no exploitation or public PoC is known, standard patch cadence is defensible, but as an interim mitigation restrict interactive logon rights to trusted accounts and monitor for crashes or restarts of the Remote Access Connection Manager service, which may signal attempted exploitation.
| Microsoft Windows (Remote Access Connection Manager / RasMan service) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
- Vendors
- microsoft
- Products
- windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.