CVE-2025-59230
Microsoft Windows Improper Access Control Vulnerability
Description
CVE-2025-59230 is a high-severity elevation of privilege vulnerability (CVSS 7.8) in the Windows Remote Access Connection Manager (RASMAN) service across multiple Microsoft Windows versions. The flaw is caused by improper access control (CWE-284), enabling a locally authenticated attacker with low privileges to escalate to higher privilege levels without any user interaction. CISA has added this vulnerability to the Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of November 4, 2025, confirming active exploitation in the wild. With an EPSS score of 8.48% (92.2nd percentile), this vulnerability has a significantly elevated probability of exploitation compared to the vast majority of known CVEs.
KEV Information
CVSS Score
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| microsoft | windows 10 1507 | < 10.0.10240.21161 |
| microsoft | windows 10 1607 | < 10.0.14393.8519 |
| microsoft | windows 10 1809 | < 10.0.17763.7919 |
| microsoft | windows 10 21h2 | < 10.0.19044.6456 |
| microsoft | windows 10 22h2 | < 10.0.19045.6456 |
| microsoft | windows 11 22h2 | < 10.0.22621.6060 |
| microsoft | windows 11 23h2 | <= 10.0.22631.6060 |
| microsoft | windows 11 24h2 | < 10.0.26100.6899 |
| microsoft | windows 11 25h2 | < 10.0.26200.6899 |
| microsoft | windows server 2008 | -; r2 |
| microsoft | windows server 2012 | -; r2 |
| microsoft | windows server 2016 | <= 10.0.14393.8519 |
| microsoft | windows server 2019 | < 10.0.17763.7919 |
| microsoft | windows server 2022 | < 10.0.20348.4294 |
| microsoft | windows server 2022 23h2 | < 10.0.25398.1913 |
| microsoft | windows server 2025 | <= 10.0.26100.6899 |
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-59230(Vendor Advisory)
- https://www.vicarius.io/vsociety/posts/cve-2025-59230-detection-script-elevation-of-privilege-vulnerability-affecting-windows-rasman(Third Party Advisory)
- https://www.vicarius.io/vsociety/posts/cve-2025-59230-mitigation-script-elevation-of-privilege-vulnerability-affecting-windows-rasman(Mitigation, Third Party Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2025-59230(US Government Resource)
Weakness Type
CWE-284: Improper Access Control
CWE-284 describes a condition where software does not properly restrict access to a resource from an unauthorized actor, or restricts access but uses mechanisms that can be bypassed. In CVE-2025-59230, the Windows Remote Access Connection Manager service fails to properly enforce access control checks, allowing a locally authenticated user with low privileges to perform operations that should be restricted to higher-privileged accounts. This weakness is one of the most common root causes of privilege escalation vulnerabilities in operating systems, as services running with elevated privileges must carefully validate that callers are authorized to request privileged operations.
Impact Analysis
The impact of CVE-2025-59230 on affected organizations is significant. An attacker who has gained initial low-level access to a Windows system can exploit this vulnerability to elevate their privileges, potentially reaching SYSTEM-level access through the Remote Access Connection Manager service. Confidentiality is fully compromised, as elevated privileges grant access to all data on the system, including stored credentials, configuration files, and sensitive business information. Integrity is equally affected because the attacker can modify system configurations, install persistent backdoors, tamper with security controls, and alter audit logs to cover their tracks. Availability is at high risk since an attacker with elevated privileges can disable services, corrupt system files, or deploy destructive payloads including ransomware.
The EPSS score of 8.48% (92.2nd percentile) places this vulnerability among the top 8% most likely to be exploited. Its presence in the KEV catalog confirms real-world exploitation. While the ransomware association is currently categorized as "Unknown" by CISA, the privilege escalation capability through RASMAN is a high-value target in post-exploitation scenarios. The Remote Access Connection Manager is a widely deployed Windows service, meaning the attack surface extends across virtually all Windows environments, from enterprise workstations to servers. Organizations should treat this as a critical patch priority, especially in environments where users have local access to systems.
Exploit Maturity
CVE-2025-59230 has confirmed active exploitation in the wild, as evidenced by its inclusion in CISA's Known Exploited Vulnerabilities (KEV) catalog with a remediation due date of November 4, 2025. The EPSS score of 8.48% (92.2nd percentile) indicates that this vulnerability is significantly more likely to be exploited than the vast majority of CVEs, reflecting real-world attacker interest.
Third-party security researchers at Vicarius have published both a detection script and a mitigation script for this vulnerability, demonstrating active community engagement and tooling availability. The existence of public detection and mitigation resources lowers the barrier for both defenders and attackers, making timely patching even more critical. The ransomware exploitation status is currently listed as "Unknown," but given that RASMAN privilege escalation provides a direct path from low-privileged access to system control, it represents a highly attractive component in multi-stage attack chains.
Remediation
-
Deploy the latest Windows security update immediately. Apply the cumulative update from Microsoft that addresses CVE-2025-59230 across all affected systems. Target minimum patch versions are: Windows 10 1507 (10.0.10240.21161), Windows 10 1607 (10.0.14393.8519), Windows 10 1809 (10.0.17763.7919), Windows 10 21H2/22H2 (10.0.19044.6456 / 10.0.19045.6456), Windows 11 22H2 (10.0.22621.6060), Windows 11 23H2 (10.0.22631.6060), and Windows 11 24H2 (10.0.26100.6899). Use Windows Update, WSUS, SCCM, or your enterprise patch management platform to ensure complete coverage.
-
Run the detection script to identify vulnerable systems. Use the publicly available detection script from Vicarius to scan your environment for systems that remain vulnerable. This helps prioritize patching efforts and identify any systems that may have been missed.
-
Apply interim mitigation if immediate patching is not possible. If certain systems cannot be patched right away, consider applying the mitigation script from Vicarius as a temporary measure. Additionally, evaluate whether the Remote Access Connection Manager service can be disabled on systems where it is not required, reducing the attack surface.
-
Investigate for signs of prior exploitation. Review Windows Security event logs for unusual privilege escalation events, unexpected service modifications to RASMAN, or suspicious process creation under elevated contexts. Correlate findings with your SIEM or EDR platform to identify potential compromise.
-
Strengthen local access controls. Limit the number of user accounts with local logon rights, enforce multi-factor authentication where possible, and apply the principle of least privilege to reduce the likelihood that an attacker can obtain the initial low-level access required for exploitation.
Technical Details
The CVSS v3.1 vector for CVE-2025-59230 is CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, producing a base score of 7.8 (High). Attack Vector (AV:L) specifies that the attacker must have local access to the target system—this vulnerability cannot be exploited remotely over the network alone. Attack Complexity (AC:L) indicates that exploitation is straightforward with no special timing, configuration, or environmental requirements. Privileges Required (PR:L) means the attacker needs only a standard, low-privileged user account on the system. User Interaction (UI:N) confirms that no victim action is required—the attacker can trigger the vulnerability independently. Scope (S:U) indicates the impact is confined to the vulnerable component's security authority, though in practice, escalation within the Windows security model can yield SYSTEM-level access. All three impact metrics—Confidentiality (C:H), Integrity (I:H), and Availability (A:H)—are rated High, reflecting full compromise of the affected system.
The vulnerability resides in the Windows Remote Access Connection Manager (RASMAN), a system service responsible for managing dial-up and VPN connections. RASMAN runs with elevated privileges and exposes interfaces that local users can interact with. The core issue is an improper access control check (CWE-284) where the service fails to adequately verify that a requesting user is authorized to perform certain privileged operations. A local attacker with a low-privileged account can invoke the vulnerable functionality to manipulate RASMAN into executing operations at a higher privilege level. This type of access control bypass in a privileged service is a classic privilege escalation pattern in Windows, where the attacker leverages the trust boundary between user-mode requests and service-level execution to gain unauthorized system access.
Frequently Asked Questions
What is CVE-2025-59230?
CVE-2025-59230 is a high-severity elevation of privilege vulnerability in the Windows Remote Access Connection Manager (RASMAN) service. It allows a locally authenticated attacker with low privileges to escalate to higher privilege levels due to improper access control. Microsoft has released security updates to address this flaw across multiple Windows versions.
Is CVE-2025-59230 being actively exploited?
Yes. CISA has confirmed active exploitation by adding CVE-2025-59230 to the Known Exploited Vulnerabilities (KEV) catalog with a remediation deadline of November 4, 2025. The EPSS score of 8.48% (92.2nd percentile) further indicates significantly elevated exploitation activity.
Which Windows versions are affected by CVE-2025-59230?
The vulnerability affects Windows 10 versions 1507, 1607, 1809, 21H2, and 22H2, as well as Windows 11 versions 22H2, 23H2, and 24H2. All systems running these versions without the latest cumulative security update are vulnerable. Server editions using the same RASMAN service may also be at risk.
Can I mitigate CVE-2025-59230 without patching?
Temporary mitigations include disabling the Remote Access Connection Manager service on systems where VPN and dial-up connectivity are not required, and applying the third-party mitigation script from Vicarius. However, these are interim measures only. The recommended and most reliable remediation is to apply the official Microsoft security update as soon as possible.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.