CVE-2026-69590
9.8Microsoft · Windows
A heap-based buffer overflow in the Windows Routing and Remote Access Service (RRAS) allows unauthenticated remote attackers to achieve code execution.
Executive summary
A critical remote code execution vulnerability in the Windows Routing and Remote Access Service (RRAS) exposes multiple versions of Windows to total system compromise by unauthenticated attackers.
Vulnerability
This is a heap-based buffer overflow (CWE-122) within the Routing and Remote Access Service (RRAS). The vulnerability is reachable via the network without user interaction or authentication (AV:N/AC:L/PR:N/UI:N).
Business impact
The ability for an unauthenticated remote attacker to execute arbitrary code on a server or workstation poses a catastrophic risk to organizational security. With a CVSS score of 9.8, this flaw facilitates full system compromise, including data exfiltration, lateral movement, and the potential for complete service disruption.
Remediation
Immediate Action: Apply the vendor-provided security updates immediately to the affected Windows builds as listed in the enrichment data. Ensure all systems are patched to at least the specified fixed versions to negate the overflow condition.
Proactive Monitoring: Monitor network traffic for unusual activity directed at RRAS-related ports and review system event logs for service crashes or unexpected process executions.
Compensating Controls: If immediate patching is not possible, disable the Routing and Remote Access Service on machines where it is not strictly required to reduce the attack surface.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
This vulnerability represents a severe threat to infrastructure integrity due to its wormable potential and lack of required authentication. IT teams should prioritize the deployment of the September 2026 security updates across all identified Windows platforms to eliminate this critical risk.
More Microsoft CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief critical section