Vulnerability record · CVE-2025-59230 · published 14 October 2025
CVE-2025-59230: Windows Remote Access Connection Manager improper access control privilege escalation
Microsoft · Windows 10 1507
Windows Remote Access Connection Manager (RASMAN) contains an improper access control flaw (CWE-284) that lets an authorized local attacker elevate privileges. It affects a broad set of Windows 10, Windows 11 and Windows Server releases, and Microsoft rates it high severity. Because it is a local privilege escalation in a core service, it is useful to attackers who already have a foothold and want SYSTEM-level rights.
Description
Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.8 high severity, broad Windows coverage and confirmed inclusion in CISA KEV with a near-term remediation deadline make this a high-priority local privilege escalation.
What it is
Windows Remote Access Connection Manager (RASMAN) contains an improper access control flaw (CWE-284) that lets an authorized local attacker elevate privileges. It affects a broad set of Windows 10, Windows 11 and Windows Server releases, and Microsoft rates it high severity. Because it is a local privilege escalation in a core service, it is useful to attackers who already have a foothold and want SYSTEM-level rights.
Impact
An attacker with low-privileged local access gains elevated privileges, with high impact to confidentiality, integrity and availability per the CVSS vector. This typically means full control of the affected host.
Attack surface
Reached locally (AV:L) with low privileges required (PR:L) and no user interaction (UI:N); the attacker must already be able to run code or commands on the target system. No remote or network vector is described.
Exploitation
CVE-2025-59230 was added to CISA KEV on 2025-10-14 with a remediation due date of 2025-11-04, indicating known exploitation in the wild. EPSS 30-day probability is about 2.7 percent (85th percentile), and CISA records no known ransomware campaign use.
What to do
- Apply the Microsoft security update for CVE-2025-59230 across all affected Windows 10, Windows 11 and Windows Server versions as the first action.
- Follow CISA KEV required action and BOD 22-01 guidance; if a patch cannot be applied, discontinue use of the affected product or apply vendor mitigations.
- Prioritize internet-facing and high-value endpoints, and confirm patch status on systems running the Remote Access Connection Manager service.
- Restrict local logon and code execution rights to reduce the pool of accounts that can trigger the flaw.
- Track the CISA due date of 2025-11-04 and report remediation status.
Detection
- Monitor for unexpected elevation of low-privileged processes interacting with the RASMAN service or related named pipes and RPC endpoints.
- Alert on suspicious process creation where a non-admin parent spawns a high-integrity or SYSTEM-level child shortly after RASMAN activity.
- Review Windows security event logs for anomalous privilege use and token elevation events on hosts with the vulnerable service.
- Use the third-party detection script referenced in the Vicarius advisory to hunt for the vulnerable condition.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2025-59230 to the Known Exploited Vulnerabilities catalog on 14 October 2025 as "Microsoft Windows Improper Access Control Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 4 November 2025.
Affected products
16 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59230 | Vendor Advisory |
| https://www.vicarius.io/vsociety/posts/cve-2025-59230-detection-script-elevation-of-privilege-vulnerability-affecting-wi | Third Party Advisory |
| https://www.vicarius.io/vsociety/posts/cve-2025-59230-mitigation-script-elevation-of-privilege-vulnerability-affecting-w | MitigationThird Party Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-59230 | US Government Resource |
Track CVE-2025-59230 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-59230), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.