A new Windows zero-day vulnerability that enables attackers to bring down the Remote Access Connection Manager (RasMan) service has free unofficial remedies.
Point-to-Point Protocol over Ethernet (PPoE), VPN, and other remote network connections are managed by RasMan, an essential Windows system service that launches automatically and operates in the background with SYSTEM-level privileges.
While investigating CVE-2025-59230, a Windows RasMan privilege escalation vulnerability exploited in attacks that was patched in October, ACROS Security, which oversees the 0patch micropatching platform, found a new denial-of-service (DoS) vulnerability.
The DoS zero-day is still unpatched in all versions of Windows, including Windows 7 through Windows 11 and Windows Server 2008 R2 through Server 2025, and has not been given a CVE ID read more about New Windows RasMan zero-day flaw gets free unofficial patches.
Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.
