Remote Code Execution Vulnerability in Windows Routing and Remote Access Service
CVE-2025-62549
8.8HIGH
Key Information:
- Vendor
Microsoft
- Status
- Vendor
- CVE Published:
- 9 December 2025
What is CVE-2025-62549?
An untrusted pointer dereference vulnerability in Windows Routing and Remote Access Service (RRAS) poses a significant risk, allowing an unauthorized attacker to execute arbitrary code over the network. This exploit can lead to severe security breaches, as it enables attackers to manipulate systems and gain control without proper authorization. Organizations must remain vigilant and apply the necessary security updates to mitigate these risks.
Affected Version(s)
Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.8688
Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.8146
Windows 10 Version 21H2 32-bit Systems 10.0.19044.0 < 10.0.19044.6691