CVE-2026-21525: 
vulnerability analysis and mitigation

Overview

CVE-2026-21525 is a NULL pointer dereference vulnerability in the Windows Remote Access Connection Manager (RASMan) service that allows an unauthenticated local attacker to cause a denial of service. Disclosed and patched on February 10, 2026, as part of Microsoft's February 2026 Patch Tuesday, it affects a wide range of Windows versions including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2), and Windows Server 2012 through 2025. It carries a CVSS v3.1 base score of 6.2 (Medium) (Microsoft MSRC, CISA KEV).

Technical details

The vulnerability is classified as CWE-476 (NULL Pointer Dereference), occurring within the Windows Remote Access Connection Manager (RASMan) service. An attacker can trigger the flaw locally without requiring any privileges or user interaction, causing the RASMan service to crash and resulting in a denial of service condition that disrupts VPN and remote access connectivity. The attack vector is local (AV:L), with low complexity and no privilege requirements, making it straightforward to exploit for any user with local access to an affected system (Microsoft MSRC, CISA KEV).

Impact

Successful exploitation crashes the RASMan service, causing a denial of service that disrupts VPN and remote access connectivity for all users on the affected system. There is no confidentiality or integrity impact; the vulnerability is limited to availability (A:H). In enterprise environments, this can directly impact business continuity by preventing legitimate users from establishing remote connections to organizational infrastructure, and could be leveraged to disrupt remote workforce access at scale (Microsoft MSRC, CISA KEV).

Exploitability

CVE-2026-21525 is actively exploited in the wild and was added to CISA's Known Exploited Vulnerabilities (KEV) catalog on February 10, 2026, with a remediation due date of March 3, 2026 (CISA KEV). No public proof-of-concept exploit code has been confirmed, though the vulnerability's low complexity and lack of privilege requirements lower the barrier for exploitation. The EPSS score is approximately 0.0283 (2.83%), and its ransomware campaign association is listed as "Unknown" in the KEV catalog. Multiple security vendors including Qualys, Tenable, and CrowdStrike flagged this as a high-priority patch given its active exploitation status (Microsoft MSRC).

Exploitation steps

  1. Reconnaissance: Identify target Windows systems running affected versions (Windows 10 1607–22H2, Windows 11 23H2–25H2, Windows Server 2012–2025) where the RASMan service is running and VPN/remote access is configured.
  2. Gain local access: Obtain any form of local access to the target system — this could be via a low-privileged user account, physical access, or a previously established foothold (e.g., via phishing or another vulnerability).
  3. Trigger the NULL pointer dereference: Send a specially crafted request or input to the Windows Remote Access Connection Manager service (RASMan) that causes it to dereference a NULL pointer. No elevated privileges or user interaction are required.
  4. Achieve denial of service: The RASMan service crashes, disrupting all VPN and remote access connectivity on the affected host. In environments relying on RASMan for remote workforce access, this can cause widespread connectivity outages (Microsoft MSRC, CISA KEV).

Indicators of compromise

  • Logs: Windows Event Log entries showing unexpected crashes or termination of the RasMan (Remote Access Connection Manager) service (Event ID 7034 – Service terminated unexpectedly; Event ID 7031 – Service terminated unexpectedly and will be restarted).
  • Process/Service: Repeated restarts or crashes of the RasMan service (svchost.exe hosting RasMan) without administrator-initiated action; application crash dumps referencing a NULL pointer dereference in RASMan-related DLLs.
  • Network: Sudden loss of VPN connectivity for multiple users simultaneously; failed remote access sessions correlating with RASMan service crashes.
  • System: Windows Error Reporting (WER) crash reports or minidumps in %SystemRoot%\Minidump or %LOCALAPPDATA%\CrashDumps referencing RASMan components.

Mitigation and workarounds

Microsoft released patches on February 10, 2026, as part of the February 2026 Patch Tuesday update. Administrators should apply the following minimum patched build versions: Windows 10 21H2/22H2 → 10.0.19044.6937 / 10.0.19045.6937; Windows 10 1809 → 10.0.17763.8389; Windows 11 23H2 → 10.0.22631.6649; Windows 11 24H2/25H2 → 10.0.26100.7781 / 10.0.26200.7781; Windows Server 2022 → 10.0.20348.4711; Windows Server 2022 23H2 → 10.0.25398.2149; Windows Server 2025 → 10.0.26100.32313; Windows Server 2016 → 10.0.14393.8868. CISA's due date for federal agencies to remediate was March 3, 2026. No vendor-provided workaround is available; patching is the only recommended remediation. Prioritize systems where RASMan/VPN services are exposed to untrusted local users (Microsoft MSRC, CISA KEV).

Community reactions

The February 2026 Patch Tuesday was widely covered due to the unusually high number of six actively exploited zero-days patched simultaneously, with CVE-2026-21525 among them. Security vendors including Qualys, Tenable, CrowdStrike, Rapid7, Sophos, and Malwarebytes all highlighted this vulnerability in their Patch Tuesday analyses, emphasizing its active exploitation and impact on VPN availability (Qualys Blog, Tenable Blog). BleepingComputer and The Hacker News reported on the broader Patch Tuesday release, noting the RASMan zero-day as a notable inclusion given its potential to disrupt enterprise remote access. CRN noted that researchers described the number of zero-days as "extraordinarily high," and Forbes urged immediate updates with the headline "Microsoft Confirms Windows Is Under Attack."

Additional resources


Source: This report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management