ZeroHour

CVE-2026-71342

mass

Use-After-Free LPE in Microsoft Windows Remote Access Connection Manager

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-71342 is a use-after-free memory-safety flaw (CWE-416) in the Windows Remote Access Connection Manager (RasMan) service. An attacker who already holds valid, low-privileged credentials on the machine can trigger the bug; the high attack-complexity score (AC:H) indicates exploitation depends on less-repeatable conditions such as specific service state or timing. Successful exploitation lets the attacker elevate privileges and fully compromise the local system, with high impact on confidentiality, integrity, and availability. Affected scope is Windows editions carrying the Remote Access Connection Manager component; the available data does not enumerate specific affected versions or builds, so defenders should check Microsoft's advisory for the exact affected range. There are no reports of in-the-wild exploitation, no public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only a 0.3% chance of exploitation in the next 30 days.

What to do: Apply the Windows security update for CVE-2026-71342 published in Microsoft's security advisory via Windows Update/WSUS as it becomes available, and prioritize multi-user systems (RDP/terminal servers, VDI, shared workstations) where standard users can sign in interactively. Since no exploitation or public PoC is known, standard patch cadence is defensible, but as an interim mitigation restrict interactive logon rights to trusted accounts and monitor for crashes or restarts of the Remote Access Connection Manager service, which may signal attempted exploitation.

Affected
Microsoft Windows (Remote Access Connection Manager / RasMan service)
Estimated exposure
mass≈1 billion+ Windows endpoints (RasMan ships by default with Windows) — Windows runs on well over a billion active devices (~70% desktop OS market share) and the Remote Access Connection Manager service is present by default on Windows client and server installs, so essentially every unpatched Windows host…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Use after free in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.