Impact
A missing authentication check within the Windows Routing and Remote Access Service (RRAS) allows an attacker who has already authenticated locally to execute privileged functions without proper authorization. This flaw represents inadequate access control (CWE‑306) and can grant the attacker elevated rights on the affected machine.
Affected Systems
Microsoft Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 24H2, 25H2, 26H1), and Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025, including Server Core installations. All of the listed builds are affected by the vulnerability.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium‑to‑high severity. The EPSS score of less than 1% implies that exploitation is currently rare, and the vulnerability does not appear in the CISA KEV catalog. The attack vector is local; an authorized local user or a compromised local account can leverage the missing authentication to elevate privileges. The impact is confined to the host system, enabling the attacker to gain higher local privileges without remote access.
OpenCVE Enrichment