Microsoft released fixes for multiple Windows local vulnerabilities affecting core services used in enterprise environments. One issue in the Remote Access Connection Manager (RasMan) service was exploited to trigger a local denial-of-service (DoS) by crashing the remote access service, which can disrupt VPN connectivity and interrupt remote access workflows on unpatched systems; Microsoft described the condition as allowing an “unauthorized attacker to deny service locally.”
Separately, Microsoft patched CVE-2026-20817, a Windows Error Reporting Service (wersvc.dll) local privilege escalation that can allow a standard user to obtain SYSTEM-level execution via ALPC messaging and insufficient authorization checks in request handling (notably around CWerService::SvcElevatedLaunch). Reporting indicates the service could be coerced into creating a new token derived from the WER service’s SYSTEM token (with SeTcbPrivilege removed but other powerful rights retained), enabling high-impact post-exploitation actions such as credential theft and full host takeover; a proof-of-concept (PoC) was also reported as available.

Get the actors, campaigns, and ATT&CK mapping behind it.
3 events from the most recent confirmed update back to the earliest known activity.
By February 2026, Microsoft had patched CVE-2026-21525 in the Windows Remote Access Connection Manager service, a local denial-of-service bug that could crash RasMan and disrupt VPN or remote access connectivity on unpatched systems. The flaw involved a NULL pointer dereference during connection negotiation and could be repeatedly triggered to sustain outages.
On February 10, 2026, public reporting disclosed technical details and proof-of-concept information for CVE-2026-20817, explaining how missing authorization checks in WER's ALPC process-creation flow could yield a near-SYSTEM token with powerful privileges. The disclosure highlighted the risk of full system compromise and credential theft on unpatched systems.
In January 2026, Microsoft patched CVE-2026-20817, a local privilege escalation vulnerability in the Windows Error Reporting Service that could let a standard user gain SYSTEM-level execution. The mitigation reportedly disabled the vulnerable functionality with a feature flag rather than adding authorization checks.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Get the adversaries, campaigns, and ATT&CK mapping behind this technique, with detections ready to deploy.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.