Impact
This weakness in the Windows Routing and Remote Access Service allows an attacker to execute arbitrary code on a vulnerable system. The flaw is a classic buffer overrun, identified as CWE‑122, which can be triggered without authentication when a specially crafted RRAS request is received. Successful exploitation results in complete loss of confidentiality, integrity, and availability, giving the attacker full control of the target machine.
Affected Systems
The vulnerability affects multiple Microsoft Windows operating systems. Windows 10 builds 1607, 1809, 21H2, and 22H2; Windows 11 builds 23H2, 24H2, 25H2, 26H1; and Windows Server releases from 2012 to 2025, including core and standard editions.
Risk and Exploitability
The CVSS score of 8.8 reflects high severity, but the EPSS score is currently unavailable, limiting insight into exploitation probability. The vulnerability is not listed in the CISA KEV catalog, suggesting no widespread exploitation yet. Attackers would typically need remote network access to the RRAS service, which listens on standard RADIUS and DNS‑PDL ports; thus, the attack vector is remote and network‑bound. If the system is exposed to untrusted networks, the risk is elevated and the position is highly attractive to threat actors.
OpenCVE Enrichment