CVE-2026-72959
8.8Microsoft · Windows
A heap-based buffer overflow in the Windows Routing and Remote Access Service (RRAS) allows an authenticated attacker to achieve remote code execution on the target system.
Executive summary
A heap-based buffer overflow vulnerability in the Microsoft Windows Routing and Remote Access Service presents a critical risk of remote code execution for affected systems.
Vulnerability
This vulnerability is a heap-based buffer overflow (CWE-122) within the Routing and Remote Access Service. It requires the attacker to hold low privileges (authenticated) to successfully trigger the flaw.
Business impact
The ability to execute arbitrary code remotely grants an attacker full control over the compromised machine, leading to potential data exfiltration, lateral movement, or complete system takeover. With a CVSS score of 8.8, this high-severity flaw poses a significant threat to organizational data integrity and availability. Immediate remediation is required to prevent unauthorized access and potential disruption of critical business services.
Remediation
Immediate Action: Apply the September 2026 security updates provided by Microsoft for the identified Windows versions to address the heap overflow.
Proactive Monitoring: Review system event logs for unusual crashes or unauthorized service restarts within the RRAS component.
Compensating Controls: Restrict network access to the Routing and Remote Access Service to trusted IP addresses only, as this service is rarely required for general-purpose workstations.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for remote code execution and the high CVSS severity, organizations should prioritize patching all affected Windows workstations and servers. Ensure that the specified build versions are updated to the fixed releases identified in the enrichment data to eliminate the underlying heap-based buffer overflow.
More Microsoft CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section