Impact
The vulnerability described as Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows an attacker to gain unauthorized access on a victim’s machine. No additional details about the technical trigger or exploitation method are provided in the official description.
Affected Systems
Affected products include Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Microsoft Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, and 2025, both in standard and Server Core configurations.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity risk. EPSS data is not available, so the probability of exploitation cannot be quantified, and the vulnerability is not listed in CISA’s KEV catalog. The description confirms that the RRAS service can be used to achieve the remote code execution, indicating that the exploitation vector involves the network-facing RRAS functionality.
OpenCVE Enrichment