Microsoft Windows RRAS Heap-Based Buffer Overflow Vulnerability Allowing Remote Code Execution

Vulnerability

A heap-based buffer overflow vulnerability has been identified in the Windows Routing and Remote Access Service (RRAS). This vulnerability allows an unauthorized attacker to execute code remotely over a network. It affects multiple versions of Windows Server, including 2008, 2012, 2016, 2019, 2022, and 2025. The vulnerability requires user interaction, as an attacker must trick a user into connecting to a malicious server via the RRAS Snap-in.

Impact

Exploitation of this vulnerability could lead to arbitrary code execution on the affected system.

Reproduction

To reproduce this vulnerability, a user must be convinced to send a request to a malicious server using the RRAS Snap-in. This can be done by initiating a connection that triggers the server to return harmful data, which could then be executed on the user's system.

Remediation

Users can apply the security updates provided by Microsoft for this vulnerability. These security updates are available through the Microsoft Update Catalog.

Added: Sep 1, 2025, 7:22 PM
Updated: Sep 1, 2025, 7:22 PM

Vulnerability Rating

Custom Algorithm
spread
8.1
impact
7.5
exploitability
6.2
remediation
7.7
relevance
0.3
threat
1.6
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.