ThreatCluster

Critical Windows Remote Access Connection Manager Vulnerabilities Disclosed

First seen 12 Dec 2025, 09:52 UTC CybersecuritynewsCyberpressGbhackers 35

Article Content

Browse articles
ThreatCluster

On December 9, 2025, two critical vulnerabilities were disclosed in the Windows Remote Access Connection Manager, identified as CVE-2025-62472 and CVE-2025-62474. These flaws allow authorized attackers with low-level privileges to escalate their access to SYSTEM-level on affected systems by exploiting uninitialized resources. Users of the affected systems are at risk of privilege escalation attacks.