ZeroHour

CVE-2026-71352

mass

Integer Underflow RCE in Microsoft Windows Remote Access Connection Manager

CVSS 3.1
8.8 high
EPSS
<1%p50
Published
()
Modified
AI analysis

CVE-2026-71352 is an integer underflow (wraparound) bug in the Windows Remote Access Connection Manager (RasMan), the built-in Windows service that manages dial-up and VPN connection handling. An authorized, low-privileged attacker who can reach the service over the network can trigger the underflow with crafted input, leading to memory corruption and arbitrary code execution without any user interaction (AV:N/AC:L/PR:L/UI:N). Successful exploitation yields remote code execution on the affected host with high impact to confidentiality, integrity, and availability, reflected in the 8.8 High CVSS score. Because RasMan ships as a standard component of Windows, essentially any Windows client or server installation is potentially affected, though the specific affected Windows versions are not enumerated in the available data and should be confirmed via Microsoft's advisory. Exploitation has not been observed: no public proof-of-concept exists, the flaw is not in CISA's KEV, and EPSS assigns only a 0.7% probability of exploitation within 30 days.

What to do: Deploy the Microsoft Windows security update that remediates CVE-2026-71352 as soon as it is available, checking the MSRC advisory for the exact affected builds since they are not listed in the available data. Because exploitation requires valid low-privileged credentials and network reachability, prioritize internet-facing VPN/RAS servers and restrict which accounts can establish connections to them. As interim detection, watch for RasMan/svchost crashes or anomalous child process activity on hosts where the service is enabled.

Affected
Microsoft Windows Remote Access Connection Manager (RasMan, Windows component)
Estimated exposure
mass≈1 billion+ Windows installations (RasMan ships with all Windows client and server editions), though only hosts reachable by low-privileged network users are… — RasMan is a standard on-box component present on essentially every Windows machine, and Microsoft's publicly stated Windows install base exceeds a billion devices, but the authenticated (PR:L) attack requirement limits practical exposure…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Integer underflow (wrap or wraparound) in Windows Remote Access Connection Manager allows an authorized attacker to execute code over a network.

Weakness
CWE-191
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.