Abstract illustration of connected devices separated by a protected security boundary.
Microsoft has issued fixes for CVE-2026-71343, Windows Remote Access Connection Manager Remote Code Execution Vulnerability, an Important-severity flaw affecting a broad span of supported Windows client and server releases.

The vulnerability is a CWE-122 heap-based buffer overflow in Windows Remote Access Connection Manager. Microsoft states: “Heap-based buffer overflow in Windows Remote Access Connection Manager allows an authorized attacker to execute code locally.”

Despite “Remote” appearing in the title, this is not a network-reachable, no-login attack. Microsoft’s advisory explains that Remote describes the attacker’s location, while the exploit itself is carried out locally. The vulnerability may also be described as Arbitrary Code Execution (ACE). An attacker or victim must execute code from the local machine for exploitation to occur.

Risk at a glance​

DetailValue
CVECVE-2026-71343
Exact titleWindows Remote Access Connection Manager Remote Code Execution Vulnerability
SeverityImportant
WeaknessCWE-122
CVSS base score7.8
CVSS temporal score6.8
CVSS vectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
Exploitation assessmentExploitation More Likely
Publicly disclosedNo
ExploitedNo
Customer action requiredYes

Publicly disclosed: No
Exploited: No
Customer action required: Yes

The CVSS vector identifies a local attack vector (AV:L), low attack complexity, low privileges required, and no user interaction requirement. Successful exploitation could have high impact on confidentiality, integrity, and availability.

The “low privileges required” rating matters. Microsoft says that any authenticated attacker could trigger the vulnerability; administrator or other elevated permissions are not required. In practical terms, organizations should treat this as a patching priority for shared workstations, jump boxes, terminal servers, and Windows servers where lower-privileged accounts can sign in. A local foothold is still needed, but that is hardly a comforting footnote after an attacker already has credentials.

What organizations should do​

Install the applicable Microsoft update and confirm the device reaches the fixed build for its Windows release and architecture. The update/build pair matters: a KB number alone is not much use if the wrong servicing branch or device architecture is selected.

Windows 10 remediation​

  • For Windows 10 Version 1607 for 32-bit Systems (x86), install KB5123099 to reach fixed build 10.0.14393.9512.
  • For Windows 10 Version 1607 for x64-based Systems, install KB5123099 to reach fixed build 10.0.14393.9512.
  • For Windows 10 Version 1809 for 32-bit Systems (x86), install KB5122876 to reach fixed build 10.0.17763.9245.
  • For Windows 10 Version 1809 for x64-based Systems, install KB5122876 to reach fixed build 10.0.17763.9245.
  • For Windows 10 Version 21H2 for 32-bit Systems (x86), install KB5122878 to reach fixed build 10.0.19044.7725.
  • For Windows 10 Version 21H2 for ARM64-based Systems, install KB5122878 to reach fixed build 10.0.19044.7725.
  • For Windows 10 Version 21H2 for x64-based Systems, install KB5122878 to reach fixed build 10.0.19044.7725.
  • For Windows 10 Version 22H2 for 32-bit Systems (x86), install KB5122878 to reach fixed build 10.0.19045.7725.
  • For Windows 10 Version 22H2 for ARM64-based Systems, install KB5122878 to reach fixed build 10.0.19045.7725.
  • For Windows 10 Version 22H2 for x64-based Systems, install KB5122878 to reach fixed build 10.0.19045.7725.

Windows 11 remediation​

  • For Windows 11 Version 23H2 for ARM64-based Systems, install KB5122880 to reach fixed build 10.0.22631.7582.
  • For Windows 11 Version 23H2 for x64-based Systems, install KB5122880 to reach fixed build 10.0.22631.7582.
  • For Windows 11 Version 24H2 for ARM64-based Systems, install KB5124008 to reach fixed build 10.0.26100.9445.
  • For Windows 11 Version 24H2 for x64-based Systems, install KB5124008 to reach fixed build 10.0.26100.9445.
  • For Windows 11 Version 25H2 for ARM64-based Systems, install KB5124008 to reach fixed build 10.0.26200.9445.
  • For Windows 11 Version 25H2 for x64-based Systems, install KB5124008 to reach fixed build 10.0.26200.9445.
  • For Windows 11 Version 26H1 for ARM64-based Systems, install KB5124012 to reach fixed build 10.0.28000.2954.
  • For Windows 11 version 26H1 for x64-based Systems, install KB5124012 to reach fixed build 10.0.28000.2954.

Windows Server remediation​

  • For Windows Server 2012 (Server Core installation) (x64), install KB5123065 to reach fixed build 6.2.9200.26349.
  • For Windows Server 2012 (x64), install KB5123065 to reach fixed build 6.2.9200.26349.
  • For Windows Server 2012 R2 (Server Core installation) (x64), install KB5123066 to reach fixed build 6.3.9600.23398.
  • For Windows Server 2012 R2 (x64), install KB5123066 to reach fixed build 6.3.9600.23398.
  • For Windows Server 2016 (Server Core installation) (x64), install KB5123099 to reach fixed build 10.0.14393.9512.
  • For Windows Server 2016 (x64), install KB5123099 to reach fixed build 10.0.14393.9512.
  • For Windows Server 2019 (Server Core installation) (x64), install KB5122876 to reach fixed build 10.0.17763.9245.
  • For Windows Server 2019 (x64), install KB5122876 to reach fixed build 10.0.17763.9245.
  • For Windows Server 2022 (Server Core installation) (x64), install KB5122882 to reach fixed build 10.0.20348.5622.
  • For Windows Server 2022 (x64), install KB5122882 to reach fixed build 10.0.20348.5622.
  • For Windows Server 2025 (Server Core installation) (x64), install KB5122871 to reach fixed build 10.0.26100.33438.
  • For Windows Server 2025 (x64), install KB5122871 to reach fixed build 10.0.26100.33438.

Why the local distinction still deserves attention​

“Local” is a condition, not a get-out-of-patching-free card. An authenticated threat actor who has obtained a standard user account, accessed a shared PC, or landed through another weakness could potentially use CVE-2026-71343 to execute code on the machine without needing administrator rights first.

The vulnerability’s 7.8 CVSS base score reflects that combination: exploitation is local and requires low privileges, yet the resulting impact is rated high across confidentiality, integrity, and availability. Microsoft’s Exploitation More Likely assessment reinforces the operational case for prompt deployment.

For enterprise administrators, the sensible order of work is straightforward:

  1. Identify Windows endpoints and servers on the listed versions.
  2. Deploy the relevant cumulative update through the organization’s normal update-management process.
  3. Restart systems where the update process requires it.
  4. Verify the resulting OS build matches the fixed build listed for that specific product and architecture.
  5. Prioritize systems with many interactive users or broad access by non-administrative accounts.

CVE-2026-71343 is an example of why Windows patch management cannot stop at hunting for internet-facing “critical” bugs. Local privilege boundaries and authenticated access remain central to real-world defense. In this case, Microsoft has supplied fixed builds across legacy Windows 10 branches, current Windows 11 releases, and Windows Server editions from 2012 through 2025. The administrative task is unglamorous—apply the right KB, validate the build, move on—but that is exactly how a heap overflow becomes a closed ticket rather than a very expensive incident.

 

References

  1. Official MSRC or vendor evidence api.msrc.microsoft.com
  2. Official MSRC or vendor evidence msrc.microsoft.com
  3. Official MSRC or vendor evidence api.msrc.microsoft.com