logo

New Windows RasMan zero-day flaw gets free, unofficial patches

ID: 881033a7-6ae2-527b-8372-a1ba7ab2c322

STIX ID: report--881033a7-6ae2-527b-8372-a1ba7ab2c322

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2025-12-12

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

**Windows RasMan zero-day DoS enables privilege escalation:** ACROS Security disclosed an unpatched denial-of-service flaw in the Remote Access Connection Manager that allows unprivileged users to crash the SYSTEM‑level service via a null-pointer during list traversal; when chained with CVE-2025-59230 this can lead to privilege escalation and code execution. ACROS/0patch has released free unofficial micropatches for affected Windows versions while Microsoft says it will address the issue in a future update.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.