
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21525 is a NULL pointer dereference vulnerability in the Windows Remote Access Connection Manager (RASMan) service that allows an unauthenticated local attacker to cause a denial of service. Disclosed and patched on February 10, 2026, as part of Microsoft's February 2026 Patch Tuesday, it affects a wide range of Windows versions including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2), and Windows Server 2012 through 2025. It carries a CVSS v3.1 base score of 6.2 (Medium) (Microsoft MSRC, CISA KEV).
The vulnerability is classified as CWE-476 (NULL Pointer Dereference), occurring within the Windows Remote Access Connection Manager (RASMan) service. An attacker can trigger the flaw locally without requiring any privileges or user interaction, causing the RASMan service to crash and resulting in a denial of service condition that disrupts VPN and remote access connectivity. The attack vector is local (AV:L), with low complexity and no privilege requirements, making it straightforward to exploit for any user with local access to an affected system (Microsoft MSRC, CISA KEV).
Successful exploitation crashes the RASMan service, causing a denial of service that disrupts VPN and remote access connectivity for all users on the affected system. There is no confidentiality or integrity impact; the vulnerability is limited to availability (A:H). In enterprise environments, this can directly impact business continuity by preventing legitimate users from establishing remote connections to organizational infrastructure, and could be leveraged to disrupt remote workforce access at scale (Microsoft MSRC, CISA KEV).
CVE-2026-21525 is actively exploited in the wild and was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on February 10, 2026, with a remediation due date of March 3, 2026 (CISA KEV). No public proof-of-concept exploit code has been confirmed, though the vulnerability's low complexity and lack of privilege requirements lower the barrier for exploitation. The EPSS score is approximately 0.0283 (2.83%), and its ransomware campaign association is listed as "Unknown" in the KEV catalog. Multiple security vendors including Qualys, Tenable, and CrowdStrike flagged this as a high-priority patch given its active exploitation status (Microsoft MSRC).
RasMan (Remote Access Connection Manager) service (Event ID 7034 – Service terminated unexpectedly; Event ID 7031 – Service terminated unexpectedly and will be restarted).RasMan service (svchost.exe hosting RasMan) without administrator-initiated action; application crash dumps referencing a NULL pointer dereference in RASMan-related DLLs.%SystemRoot%\Minidump or %LOCALAPPDATA%\CrashDumps referencing RASMan components.Microsoft released patches on February 10, 2026, as part of the February 2026 Patch Tuesday update. Administrators should apply the following minimum patched build versions: Windows 10 21H2/22H2 → 10.0.19044.6937 / 10.0.19045.6937; Windows 10 1809 → 10.0.17763.8389; Windows 11 23H2 → 10.0.22631.6649; Windows 11 24H2/25H2 → 10.0.26100.7781 / 10.0.26200.7781; Windows Server 2022 → 10.0.20348.4711; Windows Server 2022 23H2 → 10.0.25398.2149; Windows Server 2025 → 10.0.26100.32313; Windows Server 2016 → 10.0.14393.8868. CISA's due date for federal agencies to remediate was March 3, 2026. No vendor-provided workaround is available; patching is the only recommended remediation. Prioritize systems where RASMan/VPN services are exposed to untrusted local users (Microsoft MSRC, CISA KEV).
The February 2026 Patch Tuesday was widely covered due to the unusually high number of six actively exploited zero-days patched simultaneously, with CVE-2026-21525 among them. Security vendors including Qualys, Tenable, CrowdStrike, Rapid7, Sophos, and Malwarebytes all highlighted this vulnerability in their Patch Tuesday analyses, emphasizing its active exploitation and impact on VPN availability (Qualys Blog, Tenable Blog). BleepingComputer and The Hacker News reported on the broader Patch Tuesday release, noting the RASMan zero-day as a notable inclusion given its potential to disrupt enterprise remote access. CRN noted that researchers described the number of zero-days as "extraordinarily high," and Forbes urged immediate updates with the headline "Microsoft Confirms Windows Is Under Attack."
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."