Impact
This vulnerability is a missing authorization flaw in the Windows Remote Access Connection Manager. When an attacker who already has authorized local access to the system tampering operations can be performed. The flaw allows manipulation of configuration or settings that the Remote Access Connection Manager manages, potentially changing connectivity or routing behavior. Although the attack does not give control of the system itself, it can undermine the intended network connectivity or expose the system to further attacks.
Affected Systems
Affected systems include several Windows client and server releases. On clients: Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2 and Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1 on both ARM64 and x64 platforms. On servers: Microsoft Windows Server 2012 R2 (including Server Core), 2016, 2019 (Server Core), 2022 and 2025 (Server Core) running the Remote Access Connection Manager service.
Risk and Exploitability
The CVSS score of 5.5 indicates a medium severity flaw. No EPSS score is provided, so the probability of exploitation is unclear, but the flaw is not listed in CISA’s KEV catalog, suggesting no publicly known exploits exist yet. The likely attack vector is local with authorized access; an attacker who can log on to the target system can change Remote Access Connection Manager settings without proper authorization. If successful, the attacker can reconfigure remote connections, potentially exposing the system or disrupting legitimate traffic, affecting confidentiality, integrity, and availability of network connectivity. Given the lack of known exploits and the requirement for local access, the overall risk is moderate, but prompt remediation is recommended.
OpenCVE Enrichment