Back to News
Market Impact: 0.25

Microsoft RasMan DoS 0-day gets unofficial patch - and a working exploit

MSFT
Cybersecurity & Data PrivacyTechnology & Innovation
Microsoft RasMan DoS 0-day gets unofficial patch - and a working exploit

Researchers at 0patch disclosed an unpatched zero-day that allows an unprivileged user to crash the Windows Remote Access Connection Manager (RasMan) service — a null-pointer bug in circular linked-list processing that 0patch says is used in conjunction with Microsoft’s CVE-2025-59230 privilege-escalation exploit to attain SYSTEM privileges. 0patch has released an unofficial free micropatch (available via a 0patch Central trial) after notifying Microsoft, which has not yet assigned a CVE or issued an official fix, while a working exploit is publicly available and reportedly undetected by malware engines. The availability of an unpatched RasMan DoS combined with a downloadable, undetected exploit raises immediate takeover and service-disruption risk for systems handling VPN and remote connections until Microsoft provides an official remediation.

Analysis

Researchers at 0patch disclosed an unpatched zero-day that crashes the Windows Remote Access Connection Manager (RasMan) service via a null-pointer bug in circular linked-list processing, a condition the firm says is used alongside Microsoft’s previously fixed CVE-2025-59230 privilege-escalation exploit to achieve SYSTEM privileges. RasMan manages VPN and remote network connections, and the exploit requires stopping RasMan to free an RPC endpoint, enabling local privilege escalation and service disruption. 0patch has issued an unofficial, free micropatch (available via a 0patch Central trial) after notifying Microsoft, but the new DoS flaw has not been assigned a CVE, remains unpatched across Windows versions, and Microsoft has not provided public feedback. The working exploit is publicly downloadable and reportedly undetected by malware detection engines, increasing the practical attack surface in the near term. Implications for enterprise security include elevated risk of VPN/service outages and local takeover attempts until Microsoft issues an official patch and security vendors update detections; occupational exposure is highest for organizations relying on Windows-hosted VPN endpoints. Market signals show a mildly negative sentiment (article-level score -0.25 and MSFT per-ticker -0.3), implying short-term reputational and support-cost risks for Microsoft but no direct evidence yet of widespread in-the-wild exploitation.

AllMind AI Terminal

AI-powered research, real-time alerts, and portfolio analytics for institutional investors.

Request a Demo

Market Sentiment

Overall Sentiment

mildly negative

Sentiment Score

-0.25

Ticker Sentiment

MSFT-0.30

Key Decisions for Investors

  • Monitor Microsoft advisories and CVE assignment closely and consider modestly hedging or reducing near-term MSFT exposure until an official patch and vendor detections are confirmed,
  • Survey portfolio companies for dependency on Windows RasMan-managed VPNs and prioritize engagement or risk-mitigation budgets for those with high exposure,
  • Avoid opportunistic buying of MSFT or affected enterprises until proof of remediation (official patch) and updated malware-engine detections are in place, but maintain conviction if fundamentals remain intact and remediation occurs promptly