CVE-2025-49672
8.8Microsoft · Windows Routing and Remote Access Service (RRAS)
A heap-based buffer overflow in the Windows Routing and Remote Access Service (RRAS) allows an unauthenticated remote attacker to execute arbitrary code.
Executive summary
A heap-based buffer overflow vulnerability in the Microsoft Windows Routing and Remote Access Service permits unauthenticated remote attackers to achieve full system code execution.
Vulnerability
The vulnerability is a heap-based buffer overflow (CWE-122) within the RRAS component. It allows an unauthenticated attacker to trigger memory corruption and execute arbitrary code over a network.
Business impact
The potential for unauthenticated remote code execution represents a critical risk to organizational infrastructure. Successful exploitation could lead to total system compromise, unauthorized access to sensitive data, and potential lateral movement within the network, justifying the high CVSS score of 8.8.
Remediation
Immediate Action: Apply the relevant security updates provided by Microsoft in the official security update guide immediately to patch the vulnerable RRAS component.
Proactive Monitoring: Monitor system event logs for unexpected service crashes or restarts of the Routing and Remote Access Service, which may indicate exploitation attempts.
Compensating Controls: Implement network-level access controls or a Web Application Firewall (if applicable) to restrict access to RRAS ports to only trusted management subnets until patching is completed.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the severity of a remote code execution flaw in a core Windows service, organizations should prioritize the deployment of the vendor-supplied patches across all affected Server instances. Failure to remediate this vulnerability leaves critical infrastructure exposed to potential remote takeover, making immediate patching the only reliable method to eliminate the risk.