Elevation of Privilege Vulnerability in Windows Routing and Remote Access Service
CVE-2025-60713

7.8HIGH

What is CVE-2025-60713?

A vulnerability exists in the Windows Routing and Remote Access Service (RRAS) that could allow an authorized attacker to elevate privileges locally. This issue arises from the way RRAS handles untrusted pointers, potentially leading to security risks if exploited. Organizations using vulnerable versions of Windows Server should take measures to mitigate this risk.

Affected Version(s)

Windows Server 2016 (Server Core installation) x64-based Systems 10.0.14393.0 < 10.0.14393.8594

Windows Server 2016 x64-based Systems 10.0.14393.0 < 10.0.14393.8594

Windows Server 2019 (Server Core installation) x64-based Systems 10.0.17763.0 < 10.0.17763.8027

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-60713 : Elevation of Privilege Vulnerability in Windows Routing and Remote Access Service