Remote Code Execution Vulnerability in Windows Routing and Remote Access Service by Microsoft
CVE-2025-21410

8.8HIGH

Summary

A vulnerability has been identified in the Windows Routing and Remote Access Service (RRAS) that could allow an attacker to execute arbitrary code remotely. This may be exploited by sending specially crafted requests to the RRAS component, leading to potential unauthorized access and system compromise. Addressing this issue is crucial for maintaining the security and integrity of affected systems.

Affected Version(s)

Windows Server 2008 Service Pack 2 x64-based Systems 6.0.6003.0 < 6.0.6003.23117

Windows Server 2008 R2 Service Pack 1 (Server Core installation) x64-based Systems 6.1.7601.0 < 6.1.7601.27566

Windows Server 2008 R2 Service Pack 1 x64-based Systems 6.1.7601.0 < 6.1.7601.27566

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.