A newly discovered zero-day vulnerability in the Windows Remote Access Connection Manager (RasMan) service allows unprivileged users to crash the service, creating a denial-of-service (DoS) condition. This flaw, which has not yet been assigned a CVE or received an official Microsoft patch, was uncovered by ACROS Security while investigating a previously patched privilege escalation vulnerability (CVE-2025-59230). The new DoS vulnerability is critical because it enables attackers to stop the RasMan service, which is a prerequisite for exploiting certain privilege escalation bugs. A working exploit for this zero-day is publicly available, and free unofficial patches have been released by the 0patch platform to mitigate the risk until Microsoft issues an official fix.
The vulnerability affects all supported Windows versions, from Windows 7 through Windows 11 and Windows Server 2008 R2 through Server 2025. The exploit leverages a coding error in RasMan's handling of circular linked lists, causing the service to crash when a null pointer is encountered. This crash can be triggered by any unprivileged user, potentially allowing attackers to combine the DoS with other privilege escalation vulnerabilities to gain SYSTEM-level access. Microsoft has not yet responded to requests for comment or provided a timeline for an official patch, leaving organizations reliant on third-party mitigations in the interim.

See affected versions and whether adversaries are exploiting it.
4 events from the most recent confirmed update back to the earliest known activity.
Reporting on December 12 said a working exploit for the RasMan denial-of-service zero-day was publicly available and undetected by malware engines. This increased concern that attackers could use the crash bug to facilitate exploitation of the earlier RasMan privilege-escalation issue.
ACROS Security made free unofficial micropatches available through the 0Patch platform for supported and unsupported Windows versions. The fix can be applied without a reboot while Microsoft has not yet issued an official patch or CVE for the crash flaw.
Researchers at 0patch/ACROS Security identified a separate zero-day in RasMan that lets unprivileged users crash the service because of a circular linked-list handling error. The bug can be chained with CVE-2025-59230 to reopen a path to SYSTEM-level code execution or privilege escalation.
Microsoft released fixes for CVE-2025-59230 in its October 2025 security updates. The flaw allowed local attackers to gain SYSTEM privileges through the Windows Remote Access Connection Manager (RasMan) service.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecybersecuritynews.com
Open sourcego.theregister.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.