ZeroHour

CVE-2026-71343

mass

Heap Overflow in Windows Remote Access Connection Manager Allows Local Code Execution

CVSS 3.1
7.8 high
EPSS
<1%p28
Published
()
Modified
AI analysis

CVE-2026-71343 is a heap-based buffer overflow (CWE-122) in the Windows Remote Access Connection Manager service (RasMan). It is triggered by an authorized, low-privileged local user interacting with the service, and requires no user interaction or remote network access. Successful exploitation lets the attacker execute code on the affected host, with high impact on confidentiality, integrity, and availability per the CVSS score of 7.8. Any Windows system running the Remote Access Connection Manager service is affected; the specific affected Windows editions and version ranges were not included in the source data and should be confirmed in Microsoft's advisory. As of this analysis there is no known exploitation, no public proof-of-concept, and EPSS estimates only a 0.3% chance of exploitation within 30 days.

What to do: Apply Microsoft's security update for CVE-2026-71343 promptly and verify the exact affected Windows editions/versions in Microsoft's advisory. Because exploitation requires an already-authorized local user, prioritize hosts with multiple or untrusted local logons (terminal/RDP servers, shared workstations) and restrict local logon rights to trusted accounts on sensitive systems until patched.

Affected
Microsoft Windows Remote Access Connection Manager (RasMan)
Estimated exposure
masshundreds of millions of Windows devices (RasMan is a default Windows service) — The Remote Access Connection Manager service ships by default on Windows client and server installations, and Windows is estimated to run on well over a billion devices, so the potentially affected installed base is mass-scale even though…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to execute code locally.

Vendors
microsoft
Products
windows 10 1607, windows 10 1809, windows 10 21h2, windows 10 22h2, windows 11 23h2, windows 11 24h2, windows 11 25h2, windows 11 26h1, windows server 2012, windows server 2016, windows server 2019, windows server 2022
Weakness
CWE-122
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.