Back to News
Market Impact: 0.45

New Windows RasMan zero-day flaw gets free, unofficial patches

MSFT
Cybersecurity & Data PrivacyTechnology & Innovation
New Windows RasMan zero-day flaw gets free, unofficial patches

ACROS Security disclosed an unpatched Windows zero-day that allows unprivileged users to crash the Remote Access Connection Manager (RasMan) service — a SYSTEM‑level component managing VPN, PPPoE and other remote connections — across Windows 7–11 and Server 2008 R2–2025 by exploiting a null‑pointer handling bug when traversing circular linked lists. When combined with the previously patched CVE‑2025‑59230 privilege‑escalation flaw, the denial‑of‑service bug gives attackers the missing capability to impersonate RasMan and potentially achieve code execution; ACROS has released free unofficial 0patch micropatches for all affected versions while Microsoft has not yet issued an official fix. The vulnerability raises immediate enterprise risk for VPN and remote‑access infrastructure and highlights demand for rapid third‑party mitigations until Microsoft delivers an official patch.

Analysis

ACROS Security disclosed an unpatched Windows zero-day that allows unprivileged users to crash the Remote Access Connection Manager (RasMan) service across Windows 7–11 and Windows Server 2008 R2–Server 2025 by exploiting a null-pointer handling bug when traversing circular linked lists. The flaw was found while investigating CVE-2025-59230 (a privilege-escalation vulnerability patched in October); combined with that or similar elevation flaws, the denial-of-service bug provides the missing capability to impersonate RasMan and potentially achieve code execution when RasMan is not running. RasMan runs with SYSTEM privileges and manages VPN and PPPoE connections, so successful exploitation presents an immediate risk to enterprise remote-access infrastructure and increases the attack surface for privilege escalation across both supported and legacy Windows deployments. The vulnerability remains unassigned a CVE and unpatched by Microsoft, leaving organizations exposed until an official fix or stable enterprise mitigation is broadly deployed. ACROS is distributing free 0Patch micropatches that require creating an account and installing an agent; this offers rapid remediation but introduces operational, compatibility, and policy considerations around reliance on unofficial fixes. Market signals show moderately negative sentiment with a -0.6 score for MSFT and a market impact score of 0.45, implying short-term reputational and support-cost pressure for Microsoft and potential demand upside for third-party security and managed-patching vendors.

AllMind AI Terminal

AI-powered research, real-time alerts, and portfolio analytics for institutional investors.

Request a Demo

Market Sentiment

Overall Sentiment

moderately negative

Sentiment Score

-0.55

Ticker Sentiment

MSFT-0.60

Key Decisions for Investors

  • Monitor Microsoft for an official patch and deployment guidance and consider reducing near-term directional exposure to MSFT until enterprise rollout risk is clarified
  • Have portfolio companies and holdings audit RasMan/VPN exposure immediately and evaluate deploying ACROS 0Patch as a pragmatic stopgap while accounting for support and policy trade-offs
  • Increase tactical exposure to cybersecurity and managed-patching vendors that will likely benefit from accelerated enterprise demand for rapid mitigations
  • Watch for indicators of active exploitation (telemetry, incident reports, customer advisories); if widespread exploitation appears, accelerate hedging or rebalancing to protect downside