Impact
The identified weakness is a use‑after‑free bug in Windows Remote Access Connection Manager that permits an authorized user to execute code with elevated privileges. This flaw can allow a local attacker to gain higher privileges and potentially take control of the affected system. The vulnerability falls under CWE‑416 and leads to a CVSS score of 7, indicating a high‑severity local privilege escalation.
Affected Systems
Affected by the vulnerability are a broad set of Microsoft Windows operating systems, including Windows 10 versions 1607, 1809, 21H2, and 22H2, Windows 11 versions 23H2, 24H2, 25H2, 26H1, as well as Windows Server 2012 R2, Server 2016, Server 2019, Server 2022, and Server 2025 (both full and Server Core installations).
Risk and Exploitability
The CVSS score of 7 reflects a significant risk, yet the exploitability is limited to environments where the attacker already has local access. The EPSS score is listed as not available, so the probability of exploitation is uncertain. The vulnerability is not currently listed in the CISA KEV catalog, indicating no public evidence of widespread exploitation. An attacker would need to trigger the use‑after‑free condition during normal operation of Remote Access Connection Manager, which likely requires the attacker to have a user session or administrative privileges to influence privileged components.
OpenCVE Enrichment