Sceawere
Vulnerability Detail
CVE-2026-62758UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
Windows Remote Access Heap Overflow
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.8
- Creation Date
- 7h ago
- Vendor
- Microsoft
- Product
- Windows 10 Version 1607
- Attack Type
- CWE-122: Heap-based Buffer Overflow
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to elevate privileges locally.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.8",
"pubDate": "2026-08-11T17:18:28.677Z",
"pubdate": "2026-08-11T17:18:28.677Z",
"executiveSummary": "A vulnerability classified as a heap-based buffer overflow exists within the Windows Remote Access Connection Manager component.\nThe flaw allows an authorized local attacker to execute arbitrary code and successfully elevate privileges on vulnerable systems.\nThe affected product is the Windows Remote Access Connection Manager, impacting local system integrity and confidentiality.\nRisk implications include full system compromise if an attacker with local access successfully exploits the memory corruption flaw.\nAttacker capabilities are limited to local execution, requiring authorization to interact with the vulnerable subsystem.\nExploitation requirements dictate that the attacker must already possess local access to the target host and the ability to execute code in order to trigger the heap-based buffer overflow condition.",
"technicalDetails": "The vulnerability is a heap-based buffer overflow residing in the Windows Remote Access Connection Manager.\nThe root cause stems from improper bounds checking during the processing of input data within the vulnerable component, leading to a memory corruption condition on the heap.\nThe vulnerable component is responsible for managing remote network connections, exposing internal APIs or data handling routines that process maliciously crafted input.\nAuthentication requirements specify that the attacker must be authorized locally on the machine to interact with the connection manager functions.\nPrivilege requirements indicate that the attacker needs low-level local execution rights to initiate the attack sequence.\nNetwork exposure is strictly local, as the attack vector does not rely on remote network interfaces.\nThe attack flow begins when an authorized local attacker invokes the vulnerable interface within the Windows Remote Access Connection Manager with specially crafted parameters designed to exceed allocated heap buffer boundaries.\nUpon processing the oversized input, the heap buffer overflows, overwriting adjacent memory structures and control data.\nBy carefully manipulating the heap layout and payload contents, the attacker can hijack execution flow.\nThe payload behavior involves executing arbitrary code within the context of a privileged system process.\nThe post-exploitation impact results in local privilege escalation, allowing the attacker to attain elevated privileges, bypass security controls, and achieve complete administrative control over the targeted operating system."
}