Impact
The flaw in Windows Routing and Remote Access Service arises from improper link resolution before file access. The service may follow a symbolic or hard link that a local attacker can control, allowing the attacker to perform actions with higher privileges. This corresponds to CWE-59 and can lead to unauthorized changes to system configuration or installation of malware.
Affected Systems
Affected clients include Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1) and the Windows Server family from 2012 to 2025. The vulnerability is present on x86, x64 and arm64 architectures where the RRAS service is installed and running.
Risk and Exploitability
The CVSS score of 7.1 signals a high‑severity issue while the EPSS score of less than 1% suggests a low likelihood of exploitation in the near term. The flaw is not listed in the CISA KEV catalog. The attack path requires a local user with authorized access; the likely vector involves manipulating RRAS internal file references, which is inferred from the description since the official advisory does not detail the step‑by‑step execution.
OpenCVE Enrichment