Impact
An improper deallocation of memory, classified as CWE‑415, allows an authorized user to double‑free a buffer within the Windows Routing and Remote Access Service (RRAS). This flaw escalates the attacker’s privileges on the affected system, enabling them to gain higher or administrative rights that were not originally available. The vulnerability does not compromise confidentiality or network traffic directly but enables the attacker to execute arbitrary code or perform privileged actions once elevated.
Affected Systems
Microsoft Windows 10 through 22H2, Windows 11 releases up to 26H1, and Windows Server versions 2012 through 2025, including Server Core installations, are affected. The issue impacts all listed builds and processor architectures for each release.
Risk and Exploitability
The CVSS score of 7.0 indicates a medium to high severity. EPSS data is not reported, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog, suggesting limited public exploitation data. Attackers must be authenticated, implying local or otherwise authorized access is required. While no remote exploitation vector is documented, the potential to run code with elevated rights makes this a significant risk for affected machines, especially within enterprise environments where privileged accounts are common.
OpenCVE Enrichment