Impact
A flaw in the Windows Routing and Remote Access Service (RRAS) enables an attacker to execute arbitrary code on the target machine. The weakness, classified as CWE‑416, allows unauthorized code execution. The CVE description states that an attacker can gain unauthorized access to the victim’s machine, which implies that the code executed is under the attacker’s control.
Affected Systems
Affected platforms include multiple versions of Microsoft Windows 10, Windows 11, and Windows Server (2012 through 2025, including Server Core installations). Specific versions listed are Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server editions 2012, 2012 R2, 2016, 2019, 2022, 2025, along with their respective architectures. All these systems run the RRAS component, which is the entry point for the vulnerability.
Risk and Exploitability
The CVSS score of 7.5 indicates high severity. The EPSS score is not available, so current exploitation probability data is missing, and the lack of a KEV listing suggests no large‑scale exploitation has been reported yet. The likely attack vector is remote network access to the RRAS service; based on the description, it is inferred that an attacker could exploit the vulnerability over the network by sending crafted traffic to the RRAS port. The exploitation could allow the attacker to execute code with the privileges under which the RRAS service runs.
OpenCVE Enrichment