New Windows RasMan zero-day flaw gets free, unofficial patches If you’re running a small business or managing IT for one, the latest zero-day flaw in Windows’ RasMan service—that critical background beast handling VPNs and remote connections with high-level privileges—could leave your network wide open to denial-of-service attacks that crash it outright. Discovered by ACROS Security while poking at a related privilege escalation bug Microsoft patched last October, this unassigned CVE pest lets unprivileged users exploit a dumb coding error in linked list processing to trigger crashes, potentially paving the way for nastier attacks if combined with other vulnerabilities. The good news? ACROS has stepped in with free, unofficial micropatches through their 0Patch service, covering everything from Windows 7 to 11 and various Server editions, so you can slap a band-aid on it without waiting for Microsoft’s official fix. To get protected, just sign up for a free account, install the 0Patch agent, and let it work its magic automatically—though remember, this is a temporary hack until Big Blue drops a real update, so keep an eye on your security posture to avoid any surprise headaches.

Source: https://www.bleepingcomputer.com/news/microsoft/new-windows-rasman-zero-day-flaw-gets-free-unofficial-patches/