Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
CVE-2024-49086
Summary
A vulnerability has been identified in the Windows Routing and Remote Access Service (RRAS) that allows for remote code execution. This occurs when RRAS improperly handles requests. An attacker who successfully exploits this vulnerability could execute arbitrary code on the target system, potentially gaining access to sensitive information, altering system configurations, and leading to further attacks within the environment. Mitigation strategies are essential to protect systems from potential exploitation.
Affected Version(s)
Windows Server 2008 Service Pack 2 x64-based Systems 6.0.6003.0 < 6.0.6003.23016
Windows Server 2008 R2 Service Pack 1 (Server Core installation) x64-based Systems 6.1.7601.0 < 6.1.7601.27467
Windows Server 2008 R2 Service Pack 1 x64-based Systems 6.1.7601.0 < 6.1.7601.27467
References
EPSS Score
0% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved