logo

Microsoft disclosed a zero-day vulnerability affecting the NetMan service

ID: c492a67b-a205-5fcc-b877-df6ad1ae09fb

STIX ID: report--c492a67b-a205-5fcc-b877-df6ad1ae09fb

Feed Name: Kudelski Security

Threat Score
75/100

Date Published: 2025-10-15

Date Updated: 2026-07-22

...
...

CVE-2025-59230 is a locally exploitable elevation-of-privilege vulnerability in the Windows Remote Access Connection Manager (RasMan) that allows a locally authenticated attacker to execute code as SYSTEM; it is rated CVSS 7.8 and has been observed exploited in the wild. Microsoft published October 2025 patches (e.g., KB5044284, KB5044273) and recommends applying updates or disabling the RasMan service as interim mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.