← back
CVE-2026-21525

Windows Remote Access Connection Manager Denial of Service Vulnerability

CVSS 6.2 MEDIUMEPSS 5.0%● KEVCWE-476
In short

A flaw in Windows Remote Access Connection Manager causes the program to crash when it tries to use data that doesn't exist. An attacker on the same computer can trigger this crash to interrupt the service.

Technical detail

A null pointer dereference (CWE-476) in the Windows Remote Access Connection Manager allows a local, unauthenticated attacker to cause a denial of service by supplying crafted input that forces the application to access invalid memory references.

Summary generated and translated by AI from the official description.
Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally.
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →