PT-2026-7407 · Microsoft · Windows
Published
2026-02-10
·
Updated
2026-05-08
·
CVE-2026-21525
CVSS v3.1
6.2
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows versions prior to February 10, 2026
Description
A null pointer dereference exists in the Windows Remote Access Connection Manager (RasMan). This issue allows a local attacker to cause a denial-of-service by repeatedly crashing the VPN/remote-access service and disrupting connectivity. The vulnerability is actively exploited in the wild. The issue affects systems globally that utilize Windows for VPN and remote access. The vulnerability impacts the availability of the remote access service. Exploitation involves triggering the null pointer dereference within the
RasMan component, leading to service crashes.Recommendations
Apply the February 10, 2026 updates to address this vulnerability.
Monitor for abnormal
RasMan service crashes to identify potential exploitation attempts.Fix
DoS
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows