Elevation of Privilege Vulnerability in Windows Remote Access Connection Manager
CVE-2025-62472

7.8HIGH

What is CVE-2025-62472?

CVE-2025-62472 is a vulnerability related to the Windows Remote Access Connection Manager, a component of the Microsoft Windows operating system responsible for facilitating remote access to networks. This specific vulnerability arises from a flaw involving the use of uninitialized resources, allowing an authorized attacker to elevate their privileges locally. If exploited, an attacker could gain higher access levels than intended, enabling them to perform actions that would normally be restricted. Given the critical role of the Remote Access Connection Manager in managing secure connections, the elevation of privileges could lead to unauthorized access to sensitive information or critical system controls, significantly impacting the confidentiality, integrity, and availability of organizational resources.

Potential impact of CVE-2025-62472

  1. Unauthorized System Access: The vulnerability allows attackers to gain higher privileges than intended, potentially enabling them to access sensitive data or perform administrative actions on compromised systems.

  2. Compromise of Network Security: With elevated privileges, an attacker could manipulate or disable security measures, making the network more vulnerable to further attacks or data breaches.

  3. Increased Risk of Malware Deployment: As attackers gain higher access, they may deploy additional malware or exploit additional vulnerabilities within the system, leading to broader compromise of the organization’s infrastructure.

Affected Version(s)

Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.8688

Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.8146

Windows 10 Version 21H2 32-bit Systems 10.0.19044.0 < 10.0.19044.6691

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-62472 : Elevation of Privilege Vulnerability in Windows Remote Access Connection Manager