
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-62474 is an improper access control vulnerability in the Windows Remote Access Connection Manager (RASMAN) that allows an authenticated local attacker to elevate privileges. It was disclosed and patched on December 9, 2025, as part of Microsoft's December 2025 Patch Tuesday security update cycle. The vulnerability affects a broad range of Windows versions, including Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2), Windows Server 2008 R2 through Windows Server 2025. It carries a CVSS v3.1 base score of 7.8 (High) (Microsoft MSRC, Feedly).
The root cause is classified as CWE-284 (Improper Access Control) within the Windows Remote Access Connection Manager service. An authorized local user can exploit insufficient access control enforcement in RASMAN to gain elevated privileges on the affected system. The attack vector is local, requires low privileges, no user interaction, and has low attack complexity — meaning any standard user account on the system could potentially trigger the flaw. No public technical write-up or proof-of-concept code detailing the specific exploitation mechanism has been published as of the time of disclosure (Microsoft MSRC, Feedly).
Successful exploitation allows an authenticated local attacker to escalate privileges to a higher level, potentially achieving SYSTEM-level access. This could enable unauthorized modification of system settings, installation of malware or rootkits, disabling of security tools, and persistence mechanisms. The high confidentiality, integrity, and availability impact scores reflect the potential for complete system compromise following privilege escalation, which could also facilitate lateral movement within a network if the attacker pivots from the compromised host (Microsoft MSRC, Feedly).
Microsoft released patches for CVE-2025-62474 on December 9, 2025, as part of the December 2025 Patch Tuesday update. Administrators should apply the relevant cumulative updates for their Windows version (e.g., build 10.0.26100.7392 or later for Windows 11 24H2/Server 2025, 10.0.19045.6691 for Windows 10 22H2, 10.0.20348.4467 for Windows Server 2022). As interim mitigations, organizations should enforce least-privilege principles, restrict local user account permissions, and deploy endpoint detection and response (EDR) solutions to monitor for suspicious privilege escalation activity (Microsoft MSRC, Feedly).
The vulnerability was covered as part of broader December 2025 Patch Tuesday roundups by multiple security outlets. Sophos noted it as part of a significant end-of-year patch release, and Zero Day Initiative (ZDI) included it in their December 2025 security update review. CyberSecurityNews published a dedicated article on Windows RASMAN privilege escalation vulnerabilities patched in this cycle. Community coverage was largely informational, with no notable controversy or researcher-specific commentary on this CVE (Sophos, ZDI, CyberSecurityNews).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."