MSRC compact vulnerability detail

CVE-2026-21525 · Windows Remote Access Connection Manager Denial of Service Vulnerability

Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally.

Severity
Moderate
Impact
Denial of Service
CVSS
6.2 base · 5.4 temporal
Release
2026-02-10
Signals
Windows Remote Access Connection Manager Denial of Service Exploited: Yes Publicly disclosed: No Exploitability: Exploitation Detected
CWE
Patch Diff
Loading module diff metadata...
Resolved binary override
Use this when the MSRC module name cannot be mapped automatically or the resolved binary looks wrong.
Old version New version
Description
Null pointer dereference in Windows Remote Access Connection Manager allows an unauthorized attacker to deny service locally.
FAQ / Articles
No FAQ or article content was published.