Information Disclosure Vulnerability in Windows RRAS by Microsoft
CVE-2025-21203

6.5MEDIUM

Summary

An information disclosure vulnerability exists in the Windows Routing and Remote Access Service (RRAS) that could allow an unauthorized attacker to exploit a buffer over-read condition. This issue may lead to the exposure of sensitive information over a network, potentially assisting attackers in gathering insights into the system, and thereby enhancing their attack strategies. System administrators are urged to assess their configurations and implement necessary security measures as detailed in the official Microsoft advisory.

Affected Version(s)

Windows Server 2008 Service Pack 2 x64-based Systems 6.0.6003.0 < 6.0.6003.23220

Windows Server 2008 R2 Service Pack 1 (Server Core installation) x64-based Systems 6.1.7601.0 < 6.1.7601.27670

Windows Server 2008 R2 Service Pack 1 x64-based Systems 6.1.7601.0 < 6.1.7601.27670

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.