Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
widely-deployed-product-advisoryendpoint-software-vulnerabilitylateral-movement-method

Microsoft Patches Multiple Windows Elevation-of-Privilege Flaws in Networking Components

Updated 28d agoFirst seen May 25, 20267 sources

Microsoft disclosed and patched several Windows elevation-of-privilege vulnerabilities affecting networking-related components, including Windows Remote Access Connection Manager, Windows SMB Server, and Network Connection Status Indicator (NCSI). The issues tracked as CVE-2025-62474, CVE-2025-62472, CVE-2025-47955, CVE-2025-59201, and CVE-2025-58726 could allow attackers with limited access to gain higher privileges on targeted systems, extending a pattern of privilege-escalation risk previously seen in the same Remote Access Connection Manager component with CVE-2022-21914.

Among the disclosed flaws, Microsoft provided additional detail for CVE-2025-58726, describing an Important improper access control issue in Windows SMB Server that can let an authorized low-privilege attacker elevate to SYSTEM over the network by coercing a victim machine to authenticate to an attacker-controlled SMB server using a specially crafted script. Microsoft assigned the bug CWE-284 and a CVSS v3.1 score of 7.5, said exploitation required specific conditions involving an unused or nonexistent Service Principal Name on the target, and stated that the vulnerability was neither publicly disclosed nor exploited in the wild at publication and that a security fix was available.

Share:
Microsoft Patches Multiple Windows Elevation-of-Privilege Flaws in Networking Components
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

4 events from the most recent confirmed update back to the earliest known activity.

4 EVENTS
Dec 9, 20257mo ago

Microsoft publishes advisories for CVE-2025-62472 and CVE-2025-62474

Microsoft added CVE-2025-62472 and CVE-2025-62474 to the Security Update Guide as Windows Remote Access Connection Manager elevation of privilege vulnerabilities. Their publication marks formal disclosure by Microsoft on that date.

Oct 14, 20258mo ago

Microsoft publishes advisories for CVE-2025-58726 and CVE-2025-59201

Microsoft disclosed CVE-2025-58726, a Windows SMB Server elevation of privilege flaw, and CVE-2025-59201, a Network Connection Status Indicator elevation of privilege flaw, in its October 2025 Security Update Guide. For CVE-2025-58726, Microsoft said a fix was available and that the issue was neither publicly disclosed nor exploited in the wild at publication.

Jun 10, 20251y ago

Microsoft publishes advisory for CVE-2025-47955

Microsoft published CVE-2025-47955 in the Security Update Guide as a Windows Remote Access Connection Manager elevation of privilege vulnerability. The reference indicates formal disclosure and update availability on that date.

Jan 11, 20224y ago

Microsoft publishes advisory for CVE-2022-21914

Microsoft added CVE-2022-21914 to its Security Update Guide as a Windows Remote Access Connection Manager elevation of privilege vulnerability. The advisory publication indicates the vulnerability was formally disclosed by Microsoft on that date.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Microsoft Patches Multiple Windows Elevation-of-Privilege Flaws in Networking Components | Mallory