Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2024-49085
Summary
The vulnerability in Windows Routing and Remote Access Service (RRAS) allows an attacker to execute arbitrary code on the affected system. This issue arises when the RRAS does not properly handle certain requests, potentially enabling a remote attacker to compromise the system through specially crafted network packets. Exploiting this vulnerability could lead to unauthorized access and control over the affected systems, emphasizing the need for organizations to apply available updates and ensure their network services are secure.
Affected Version(s)
Windows Server 2008 Service Pack 2 x64-based Systems 6.0.6003.0 < 6.0.6003.23016
Windows Server 2008 R2 Service Pack 1 (Server Core installation) x64-based Systems 6.1.7601.0 < 6.1.7601.27467
Windows Server 2008 R2 Service Pack 1 x64-based Systems 6.1.7601.0 < 6.1.7601.27467
References
EPSS Score
0% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved