CVE-2025-59230
Microsoft · Published October 14, 2025
7.8
CVSS v3.1
HIGHCISA KEV — Federal agencies must patch by deadline
Actively exploited in the wild
Patch availableGet patch
Description
Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
Affected Products
- Windows 10 1507 < 10.0.10240.21161
- Windows 10 1607 < 10.0.14393.8519
- Windows 10 1809 < 10.0.17763.7919
- Windows 10 21h2 < 10.0.19044.6456
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H