Impact
A heap-based buffer overflow exists in the Windows Routing and Remote Access Service (RRAS). When triggered by an authorized local user, the flaw allows the attacker to gain elevated privileges on the affected Windows systems. This represents a classic stack or heap overflow weakness (CWE‑122) that can be abused to execute arbitrary code with higher rights.
Affected Systems
The vulnerability impacts a broad set of Microsoft operating systems: Windows 10 versions 1607, 1809, 21H2 and 22H2; Windows 11 versions 24H2, 25H2 and 26H1; and Windows Server releases 2012 R2, 2016, 2019, 2022 and 2025, including both general and Server Core installations. All affected editions are included in the list of affected products identified by Microsoft.
Risk and Exploitability
With a CVSS score of 7.8 and an EPSS rate of less than 1 %, the risk profile suggests that while exploitation is feasible, it is unlikely to be widely automated or performed at scale. The flaw does not appear in the CISA KEV catalog, and the attack path requires a local user with authorized privileges, as indicated by the description. The attacker’s goal is to elevate privileges locally, potentially to SYSTEM level, thereby compromising system confidentiality, integrity and availability.
OpenCVE Enrichment