Remote Code Execution Vulnerability in Windows Routing and Remote Access Service
CVE-2025-21208

8.8HIGH

Summary

The Windows Routing and Remote Access Service (RRAS) is susceptible to a remote code execution vulnerability that can be exploited by an attacker to run arbitrary code on the affected system. This can lead to a range of security risks, including unauthorized access to sensitive data and the ability to take control of compromised systems. Users are advised to apply the patches released by Microsoft as soon as possible to mitigate the risk associated with this vulnerability.

Affected Version(s)

Windows Server 2008 Service Pack 2 x64-based Systems 6.0.6003.0 < 6.0.6003.23117

Windows Server 2008 R2 Service Pack 1 (Server Core installation) x64-based Systems 6.1.7601.0 < 6.1.7601.27566

Windows Server 2008 R2 Service Pack 1 x64-based Systems 6.1.7601.0 < 6.1.7601.27566

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.