Impact
The vulnerability is a Remote Code Execution flaw in the Windows Routing and Remote Access Service (RRAS). An attacker who successfully exploits it can run arbitrary code with the privileges of the service, potentially compromising the entire system. The weakness is a classic heap-based buffer overflow, as indicated by the associated CWE-122.
Affected Systems
Affected products include multiple Windows 10 and Windows 11 client releases (Version 1607, 1809, 21H2, 22H2, 23H2, 24H2, 25H2, 26H1) as well as Windows Server editions from 2012 through 2025, covering both standard and Server Core installations.
Risk and Exploitability
The CVSS score of 9.8 reflects a critical severity and indicates that the flaw can be exploited remotely without authentication. The EPSS score is not available, but the absence of a KEV listing does not reduce the risk; attackers typically target high-impact RCE flaws. It is inferred that the attack vector involves remote interaction with the RRAS service, requiring the attacker to connect to the host over the network. No official CNA workaround is provided, so the vulnerability must be remediated through patching and network hardening.
OpenCVE Enrichment