CVE-2025-59230

Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

  • Published Oct 14, 2025
  • CVSS 7.8 high
  • 2.7% chance of exploitation in the next 30 days (EPSS)
  • In CISA's Known Exploited Vulnerabilities catalog

Affected software

CVE-2025-59230 at the National Vulnerability Database