CVE-2025-50162

8.0

Microsoft · Windows Routing and Remote Access Service (RRAS)

A heap-based buffer overflow in the Windows Routing and Remote Access Service (RRAS) allows an authenticated attacker to execute arbitrary code over a network.

Executive summary

A heap-based buffer overflow vulnerability in Microsoft Windows RRAS allows authenticated attackers to achieve remote code execution, posing a significant threat to server integrity.

Vulnerability

This is a heap-based buffer overflow (CWE-122) within the Routing and Remote Access Service. The vulnerability requires the attacker to be authenticated with low privileges to trigger the flaw, which can then be leveraged to execute code remotely.

Business impact

The ability for an authenticated attacker to execute arbitrary code on a server hosting RRAS represents a critical security risk. Successful exploitation could lead to full system compromise, unauthorized data access, and lateral movement within the corporate network. With a CVSS score of 8.0, this vulnerability is categorized as High severity, necessitating prompt attention to prevent potential service disruption or breach.

Remediation

Immediate Action: Administrators must apply the security updates provided in the official Microsoft Security Update Guide immediately to remediate the affected RRAS components.

Proactive Monitoring: Security teams should monitor network traffic and event logs for unusual activity or unexpected service crashes associated with the RRAS process.

Compensating Controls: If immediate patching is not feasible, restrict network access to the RRAS service to trusted internal IP addresses only, and employ host-based intrusion detection systems to identify malicious patterns.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the potential for remote code execution within core server infrastructure, this vulnerability should be prioritized within the standard patch management cycle. Organizations running legacy Windows Server versions must ensure they apply the relevant security updates to mitigate the risk of exploitation. Confirm successful installation of the patches by verifying the build numbers of the affected service components.

More Microsoft CVEs all →

History

  1. Disclosed CVE record published
  2. Published in the daily brief high section
  3. Published in the daily brief high section
  4. Analyst report written
  5. Fix documented version 6.1.7601.27872 per CVE record

Sources