CVE-2025-47998

8.8

Microsoft · Windows Routing and Remote Access Service (RRAS)

A heap-based buffer overflow in the Windows Routing and Remote Access Service allows an unauthenticated attacker to achieve remote code execution over a network.

Executive summary

A critical heap-based buffer overflow vulnerability in Microsoft Windows Routing and Remote Access Service (RRAS) permits unauthenticated remote code execution, posing a severe risk to server integrity.

Vulnerability

This vulnerability involves a heap-based buffer overflow and integer overflow in RRAS, which can be triggered by an unauthenticated attacker sending specially crafted network packets to the service.

Business impact

The vulnerability carries a CVSS score of 8.8, reflecting its high potential for total system compromise. Successful exploitation allows an attacker to execute arbitrary code with elevated privileges, potentially leading to unauthorized data exfiltration, lateral movement within the network, and complete service disruption of the affected domain controllers or infrastructure servers.

Remediation

Immediate Action: Apply the security updates provided by Microsoft in the official update guide at https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-47998 immediately.

Proactive Monitoring: Monitor network traffic for anomalous RRAS service requests and review system event logs for crashes or unauthorized process execution associated with the service.

Compensating Controls: Implement network-level access controls to restrict access to the RRAS service to trusted IP addresses only, and utilize a Web Application Firewall or Intrusion Prevention System to inspect traffic for malformed packets targeting the service port.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the critical nature of this vulnerability and its potential for unauthenticated remote code execution, organizations must prioritize patching the affected Windows Server environments. Administrators should test and deploy the vendor-supplied updates as part of their next maintenance cycle or via emergency change procedures to eliminate this high-risk attack vector.

More Microsoft CVEs

Sources