Impact
This vulnerability in the Windows Routing and Remote Access Service allows an attacker to execute arbitrary code on the target machine. The flaw, identified as a use‑after‑free error, can be triggered to override normal program flow and run malicious payloads, granting full control over the system. Consequently, confidentiality, integrity, and availability of the affected device can be compromised, enabling data exfiltration, persistence, or further lateral movement.
Affected Systems
The flaw affects a wide range of Microsoft Windows operating systems, including Windows 10 versions 1607, 1809, 21H2, and 22H2, Windows 11 versions 23H2, 24H2, 25H2, and 26H1, and several Windows Server releases such as 2012, 2012 R2, 2016, 2019, 2022, and 2025. All editions that include the Routing and Remote Access Service are susceptible.
Risk and Exploitability
The CVSS score of 8.1 indicates a high severity vulnerability. EPSS is not available, and the vulnerability is not listed in the CISA KEV catalog, implying that, at present, the exploitation probability is uncertain and may not have active exploit code in the wild. The likely attack vector is through remote access to the RRAS service over a network connection, which the service exposes. Based on the description, an attacker with network connectivity to a target device could leverage the flaw to run code, leading to full system compromise.
OpenCVE Enrichment