CVE-2026-72950
8.8Microsoft · Windows
A heap-based buffer overflow in the Windows Routing and Remote Access Service (RRAS) allows an authenticated attacker to achieve remote code execution.
Executive summary
A critical remote code execution vulnerability exists in the Windows Routing and Remote Access Service that could allow an authenticated attacker to take full control of affected systems.
Vulnerability
This vulnerability is caused by a heap-based buffer overflow (CWE-122) within the Routing and Remote Access Service. The attack requires the adversary to have low-level privileges on the target system to trigger the flaw over the network.
Business impact
Successful exploitation of this vulnerability allows an attacker to execute arbitrary code with elevated privileges, leading to a total compromise of system confidentiality, integrity, and availability. With a CVSS score of 8.8, this flaw poses a severe risk to organizational infrastructure, as it could facilitate lateral movement, data exfiltration, or the deployment of ransomware within the internal network.
Remediation
Immediate Action: Apply the September 2026 security updates provided by Microsoft to the affected Windows versions listed above.
Proactive Monitoring: Monitor network traffic for unusual activity directed at RRAS ports and review system event logs for crashes or service failures that may indicate overflow attempts.
Compensating Controls: Restrict access to the Routing and Remote Access Service to trusted users and networks, and ensure that host-based firewalls are configured to block unauthorized traffic.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for total system compromise, administrators should prioritize the deployment of the vendor-supplied patches to all affected Windows endpoints. Failure to address this vulnerability exposes the organization to significant risk from authenticated adversaries capable of exploiting memory corruption flaws to gain persistent system access.
More Microsoft CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section