CVE-2025-59230: Microsoft Windows Improper Access Control Vulnerability
Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
Other sources
Microsoft Windows contains an improper access control vulnerability in Windows Remote Access Connection Manager which could allow an authorized attacker to elevate privileges locally.
— CISA
Windows Remote Access Connection Manager Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.6899Patch KB5066835 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.21161Patch KB5066837 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.22824Patch KB5066873 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.7919Patch KB5066586 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.8519Patch KB5066836 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.25722Patch KB5066875 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.27974Patch KB5066876 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.23571Patch KB5066877 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.1913Patch KB5066780 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.6060Patch KB5066793 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.6899Patch KB5066835 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.6456Patch KB5066791 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.6060Patch KB5066793 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.6456Patch KB5066791 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.4294Patch KB5066782
Event History
Frequently Asked Questions
What is the severity of CVE-2025-59230?
CVE-2025-59230 is classified as a high severity vulnerability due to its potential to allow privilege escalation.
How do I fix CVE-2025-59230?
To fix CVE-2025-59230, apply the latest security patch provided by Microsoft for the affected Windows version.
Which Windows versions are affected by CVE-2025-59230?
CVE-2025-59230 affects multiple versions of Windows including Windows 10, Windows 11, and various Windows Server editions.
What type of vulnerability is CVE-2025-59230?
CVE-2025-59230 is an improper access control vulnerability within Windows Remote Access Connection Manager.
Who is at risk from CVE-2025-59230?
Authorized attackers with local access to a vulnerable system could exploit CVE-2025-59230 to elevate their privileges.