CVE-2026-21525

unknown KEV
Published 2026-02-10 ยท Modified 2026-02-10
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
1.5

Description

Microsoft Windows Remote Access Connection Manager contains a NULL pointer dereference that could allow an unauthorized attacker to deny service locally.

CISA KEV

Vendor
Microsoft
Product
Windows
Due date
2026-03-03

Predictions

Exploit likelihood
99%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Microsoft Security Response Center ยท View original โ†— ยท proprietary-no-redistribution
Full prose not cached โ€” VIR stores only structured fields (affected/fixed versions, references) for this source. Click "View original" above for the vendor's full advisory.

Affected

VendorProductVersion
microsoftWindows Server 2012
microsoftWindows Server 2012 (Server Core installation)
microsoftWindows Server 2012 R2
microsoftWindows Server 2012 R2 (Server Core installation)
microsoftMicrosoft Excel 2016 (32-bit edition)
microsoftMicrosoft Excel 2016 (64-bit edition)
microsoftMicrosoft Word 2016 (32-bit edition)
microsoftMicrosoft Word 2016 (64-bit edition)
microsoftMicrosoft Outlook 2016 (32-bit edition)
microsoftMicrosoft Outlook 2016 (64-bit edition)
microsoftWindows Server 2016
microsoftOffice Online Server
microsoftWindows 10 Version 1607 for 32-bit Systems
microsoftWindows 10 Version 1607 for x64-based Systems
microsoftWindows Server 2016 (Server Core installation)
microsoftMicrosoft SharePoint Enterprise Server 2016
microsoftWindows 10 Version 1809 for 32-bit Systems
microsoftWindows 10 Version 1809 for x64-based Systems
microsoftWindows Server 2019
microsoftWindows Server 2019 (Server Core installation)
microsoftMicrosoft Office 2019 for 32-bit editions
microsoftMicrosoft Office 2019 for 64-bit editions
microsoftMicrosoft SharePoint Server 2019
microsoftVisual Studio Code
microsoftWindows Admin Center
microsoftMicrosoft Edge (Chromium-based)
microsoftMicrosoft Teams
microsoftPower BI Report Server
microsoftMicrosoft 365 Apps for Enterprise for 32-bit Systems
microsoftMicrosoft 365 Apps for Enterprise for 64-bit Systems

Exploits

Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.