CVE-2025-59230: Microsoft Windows Improper Access Control Vulnerability

Published Oct 14, 2025
·
Updated

Improper access control in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.

Other sources

Microsoft Windows contains an improper access control vulnerability in Windows Remote Access Connection Manager which could allow an authorized attacker to elevate privileges locally.

CISA

Windows Remote Access Connection Manager Elevation of Privilege Vulnerability

Microsoft

Affected Software

82 affected componentsFixes available
Microsoft Windows
Microsoft Windows Server 2025
Microsoft Windows 10
Microsoft Windows 11=24H2
Microsoft Windows 10=1607
Microsoft Windows 10=1809
Microsoft Windows 10
Microsoft Windows 10=1809
Microsoft Windows Server 2012 R2
Microsoft Windows Server 2012
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2012 R2
Microsoft Windows Server 2008
Microsoft Windows Server 2008 R2
Microsoft Windows Server 2012
Microsoft Windows Server 2008
Microsoft Windows Server 2008
Microsoft Windows 10=1607
Microsoft Windows Server 2008
Microsoft Windows Server 2016
Microsoft Windows Server 2016
Microsoft Windows 10 1507<10.0.10240.21161
Microsoft Windows 10 1507<10.0.10240.21161
Microsoft Windows 10 1607<10.0.14393.8519
Microsoft Windows 10 1607<10.0.14393.8519
Microsoft Windows 10 1809<10.0.17763.7919
Microsoft Windows 10 1809<10.0.17763.7919
Microsoft Windows 10 21h2<10.0.19044.6456
Microsoft Windows 10 22h2<10.0.19045.6456
Microsoft Windows 11 22h2<10.0.22621.6060
Microsoft Windows 11 23h2<=10.0.22631.6060
Microsoft Windows 11 24h2<10.0.26100.6899
Microsoft Windows 11 25h2<10.0.26200.6899
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=r2-sp1
Microsoft Windows Server 2012
Microsoft Windows Server 2012=r2
Microsoft Windows Server 2016<=10.0.14393.8519
Microsoft Windows Server 2019<10.0.17763.7919
Microsoft Windows Server 2022<10.0.20348.4294
Microsoft Windows Server 2022 23h2<10.0.25398.1913
Microsoft Windows Server 2025<=10.0.26100.6899
Microsoft Windows 11=24H2
10.0.26100.6899
Microsoft Windows 10<10.0.10240.21161
10.0.10240.21161
Microsoft Windows Server 2025<10.0.26100.6899
10.0.26100.6899
Microsoft Windows Server 2012 R2<6.3.9600.22824
6.3.9600.22824
Microsoft Windows 10=1809
10.0.17763.7919
Microsoft Windows 10=1607
10.0.14393.8519
Microsoft Windows Server 2012<6.2.9200.25722
6.2.9200.25722
Microsoft Windows 10=1809
10.0.17763.7919
Microsoft Windows Server 2012 R2<6.3.9600.22824
6.3.9600.22824
Microsoft Windows Server 2008 R2<6.1.7601.27974
6.1.7601.27974
Microsoft Windows Server 2012<6.2.9200.25722
6.2.9200.25722
Microsoft Windows Server 2008 R2<6.1.7601.27974
6.1.7601.27974
Microsoft Windows 10<10.0.10240.21161
10.0.10240.21161
Microsoft Windows Server 2008<6.0.6003.23571
6.0.6003.23571
Microsoft Windows Server 2008<6.0.6003.23571
6.0.6003.23571
Microsoft Windows Server 2008<6.0.6003.23571
6.0.6003.23571
Microsoft Windows Server 2008<6.0.6003.23571
6.0.6003.23571
Microsoft Windows Server 2016<10.0.14393.8519
10.0.14393.8519
Microsoft Windows 11=24H2
10.0.26100.6899
Microsoft Windows Server 2022, 23H2 Edition<10.0.25398.1913
10.0.25398.1913
Microsoft Windows 11=23H2
10.0.22631.6060
Microsoft Windows 11=23H2
10.0.22631.6060
Microsoft Windows Server 2016<10.0.14393.8519
10.0.14393.8519
Microsoft Windows 11=25H2
10.0.26200.6899
Microsoft Windows 10=1607
10.0.14393.8519
Microsoft Windows 11=25H2
10.0.26200.6899
Microsoft Windows Server 2025<10.0.26100.6899
10.0.26100.6899
Microsoft Windows 10=22H2
10.0.19045.6456
Microsoft Windows 11=22H2
10.0.22621.6060
Microsoft Windows 10=22H2
10.0.19045.6456
Microsoft Windows 10=22H2
10.0.19045.6456
Microsoft Windows 11=22H2
10.0.22621.6060
Microsoft Windows 10=21H2
10.0.19044.6456
Microsoft Windows 10=21H2
10.0.19044.6456
Microsoft Windows Server 2022<10.0.20348.4294
10.0.20348.4294
Microsoft Windows 10=21H2
10.0.19044.6456
Microsoft Windows Server 2022<10.0.20348.4294
10.0.20348.4294
Microsoft Windows Server 2019<10.0.17763.7919
10.0.17763.7919
Microsoft Windows Server 2019<10.0.17763.7919
10.0.17763.7919

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 10.0.26100.6899Patch KB5066835
  2. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 10.0.10240.21161Patch KB5066837
  3. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 6.3.9600.22824Patch KB5066873
  4. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 10.0.17763.7919Patch KB5066586
  5. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 10.0.14393.8519Patch KB5066836
  6. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 6.2.9200.25722Patch KB5066875
  7. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 6.1.7601.27974Patch KB5066876
  8. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 6.0.6003.23571Patch KB5066877
  9. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 10.0.25398.1913Patch KB5066780
  10. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 10.0.22631.6060Patch KB5066793
  11. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 10.0.26200.6899Patch KB5066835
  12. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 10.0.19045.6456Patch KB5066791
  13. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 10.0.22621.6060Patch KB5066793
  14. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 10.0.19044.6456Patch KB5066791
  15. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Fixed in 10.0.20348.4294Patch KB5066782

Event History

Oct 14, 2025
CVE Published
via CISA·12:00 AM
Known Exploited
via CISA·12:00 AM
Data Sourced
via CISA·12:00 AM
RemedyDescriptionAffected Software
Data Sourced
via Microsoft·07:00 AM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·07:00 AM
Affected Software
Updated
via Microsoft·07:00 AM
Description
Updated
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Description
CVE Published
via MITRE·05:01 PM
Data Sourced
via MITRE·05:01 PM
DescriptionSeverity
Data Sourced
via NVD·05:16 PM
DescriptionSeverityWeaknessAffected Software
Dec 12, 2025
News Published
via The Register·10:29 PM
News Published
via The Register·10:33 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2025-59230?

CVE-2025-59230 is classified as a high severity vulnerability due to its potential to allow privilege escalation.

2

How do I fix CVE-2025-59230?

To fix CVE-2025-59230, apply the latest security patch provided by Microsoft for the affected Windows version.

3

Which Windows versions are affected by CVE-2025-59230?

CVE-2025-59230 affects multiple versions of Windows including Windows 10, Windows 11, and various Windows Server editions.

4

What type of vulnerability is CVE-2025-59230?

CVE-2025-59230 is an improper access control vulnerability within Windows Remote Access Connection Manager.

5

Who is at risk from CVE-2025-59230?

Authorized attackers with local access to a vulnerable system could exploit CVE-2025-59230 to elevate their privileges.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203