EXPOSURES › CVE-2025-59230
CVE-2025-59230
HIGH ⌖ ON CISA KEV · EXPLOITEDAuthorized attackers could elevate privileges on Windows systems due to an improper access control vulnerability in the Remote Access Connection Manager.
An unpatched vulnerability in Microsoft's Windows Remote Access Connection Manager allows authorized attackers to locally elevate their privileges, posing a high security risk to DIB organizations.
Shame score — Authorized attackers could exploit an unpatched local privilege escalation vulnerability.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Microsoft Windows contains an improper access control vulnerability in Windows Remote Access Connection Manager which could allow an authorized attacker to elevate privileges locally.
| PRODUCT | STATUS |
|---|---|
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |