Skip to content
ThreatCluster

Critical Windows Remote Access Connection Manager Vulnerabilities Disclosed

First seen 12 Dec 2025, 09:52 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 13:27 UTC

On December 9, 2025, two critical vulnerabilities were disclosed in the Windows Remote Access Connection Manager, identified as CVE-2025-62472 and CVE-2025-62474. These flaws allow authorized attackers with low-level privileges to escalate their access to SYSTEM-level on affected systems by exploiting uninitialized resources. Users of the affected systems are at risk of privilege escalation attacks.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 213d ago How this analysis works

More articles in this cluster (4)

Following this threat?

Track CVE-2025-62472 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed