Impact
This vulnerability is a null pointer dereference in the Windows Routing and Remote Access Service (RRAS). When triggered, it can abruptly terminate the RRAS process, interrupting routing functions and causing network services to become unavailable. This constitutes a denial of service of moderate severity, as indicated by the CWE-476 classification and the CVSS score of 6.5. The attack can potentially be performed by an authorized or privileged user, indicating a local or enterprise-level threat vector rather than a purely remote threat.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Microsoft Windows 11 versions 23H2, 24H2, 25H2, 26H1; Microsoft Windows Server 2012, 2012 R2, 2016, 2019, 2022, 2025 – all Core and non‑Core installations.
Risk and Exploitability
With a CVSS score of 6.5 and an EPSS score of 1%, the exploitability is moderate but not negligible. The vulnerability is listed outside the CISA KEV catalog, indicating no widespread exploitation has been reported yet. Because the description specifies an "authorized attacker", the likely attack would require local or administrative privileges, limiting the scope to compromised machines or networks where RRAS is configured. However once compromised, the attacker can force RRAS to crash, disrupting routing and remote access services until the system is restarted or patched.
OpenCVE Enrichment