A Microsoft zero-day vulnerability that allows an unprivileged user to crash the Windows Remote Access Connection Manager (RasMan) service now has a free, unofficial patch - with no word as to when Redmond plans to release an official one - along with a working exploit circulating online. Researchers from 0patch, the micropatching site, uncovered the denial-of-service (DoS) bug while investigating CVE-2025-59230, a Windows RasMan privilege escalation vulnerability that Redmond fixed in October, but not before attackers found and exploited the vulnerability. RasMan is a critical Windows service that manages VPN and other remote network connections, and CVE-2025-59230 allows an authorized attacker to elevate privileges locally and gain SYSTEM privileges. It essentially takes advantage of the fact that when RasMan is not running, any process can impersonate RasMan and execute code on an RPC endpoint - a condition the exploit depends on. The exploit is freely downloadable, so one can assume it has been and will be obtained by many interested parties, possibly including malicious actors "Consequently, a working exploit must therefore be able to (also) stop the RasMan service to release said RPC endpoint," ACROS Security CEO and 0patch co-founder Mitja Kolsek said in a Friday blog. "And this was the second, non-obvious vulnerability that the CVE-2025-59230 exploit we had found utilizes: one that allows an unprivileged user to crash the RasMan service. Without this capability, CVE-2...
Microsoft RasMan 0-day gets an unofficial patch and exploit
The Register
·Jessica Lyons
·Published Dec 12, 2025
·Updated
Affected Software
1 affected component
Microsoft Windows
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a zero-day vulnerability in the Windows Remote Access Connection Manager (RasMan) service and the emergence of an unofficial patch.
2
What security implications are discussed in the article?
The article highlights the risk of unprivileged users crashing the RasMan service, which can disrupt remote access functionality.
3
What products or software are affected by this vulnerability?
The vulnerability affects Microsoft Windows, specifically the RasMan service.
4
Is there an official patch available for this vulnerability?
No, the article states that there is currently no official patch from Microsoft.
5
How is the exploit being used according to the article?
A working exploit for the vulnerability is circulating online, potentially allowing attackers to exploit the zero-day.