Impact
The vulnerability is a remote code execution flaw in the Windows Routing and Remote Access Service (RRAS). An attacker can gain unauthorized access to the victim's machine when the service is reachable. The flaw is classified as a buffer overflow (CWE‑122), which may allow arbitrary code execution and full system compromise.
Affected Systems
Affected Microsoft operating systems include Windows 10 versions 1607, 1809, 21H2, and 22H2; Windows 11 versions 23H2, 24H2, 25H2, and 26H1; and Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, and 2025, including Server Core installations and support for x86, x64, and ARM64 architectures.
Risk and Exploitability
The CVSS score of 7.5 flags this as a high‑severity vulnerability. No EPSS score is available, leaving the likelihood of exploitation uncertain. The vulnerability is listed as not in the CISA KEV catalog. Attackers can exploit it over the network when the RRAS service is enabled and reachable, so systems exposing RRAS to untrusted networks face the greatest risk.
OpenCVE Enrichment