LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2025-59230: Microsoft Windows Improper Access Control Vulnerability

RBRecent Breaches Vulnerability Intelligence·Oct 14, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Nov 4, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2025-59230 to its Known Exploited Vulnerabilities catalog on Oct 14, 2025, with a federal patch deadline of Nov 4, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Microsoft Windows contains an improper access control vulnerability in Windows Remote Access Connection Manager which could allow an authorized attacker to elevate privileges locally.

CVE-2025-59230 is an improper access control vulnerability in Microsoft Windows that affects the Windows Remote Access Connection Manager component. An authorized attacker can use it to elevate privileges locally on a system where they already have some level of access.

Local privilege escalation flaws of this type matter because they turn limited footholds into broader control of the host. Defenders should prioritize identification and remediation on Windows systems that use or expose Remote Access Connection Manager functionality, confirming all details against the vendor advisory.

How it works

The vulnerability is classified as CWE-284 (Improper Access Control). In this case the flaw resides in Windows Remote Access Connection Manager. An attacker who is already authorized on the system can abuse the weak access-control checks to obtain higher privileges than intended.

Because the elevation is local, the attacker must first possess a valid foothold—such as a low-privilege user session or process. Once that foothold exists, the improper access control allows the attacker to escalate. Exact exploitation mechanics are not detailed in the available summary; treat any public proof-of-concept claims with caution and verify behavior against the vendor advisory and your own testing.

Am I affected? How to find it in your systems

The vulnerability impacts Microsoft Windows installations that include the Windows Remote Access Connection Manager. This component is commonly present on client and server editions that support remote-access or VPN-related services.

How to remediate

Apply the vendor-supplied update for CVE-2025-59230 as the primary remediation. Follow Microsoft’s instructions exactly; the CISA-required action is to apply mitigations per those vendor instructions, follow applicable BOD 22-01 guidance for any cloud-hosted Windows instances, or discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Until the official update can be applied, reduce the attack surface with compensating controls focused on local privilege escalation.

These measures do not eliminate the vulnerability; they only buy time until the vendor update is installed.

If your data may have been exposed

Actively exploited local-privilege-escalation vulnerabilities can lead to full host compromise and subsequent data exposure. Ransomware use of this specific CVE is not documented. If you suspect an attacker has already elevated privileges, treat the host as compromised: isolate it, collect forensic artifacts, rotate credentials, and hunt for lateral movement. As a routine hygiene step, you can run a free exposure scan of your email addresses against known breach data sets to determine whether any of your accounts appear in previously disclosed incidents.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedMicrosoft · Windows
WeaknessCWE-284
Added to CISA KEVOct 14, 2025
Federal patch deadlineNov 4, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities