Heap-Based Buffer Overflow in Microsoft Windows Routing and Remote Access Service
CVE-2026-57096
7.8HIGH
Key Information:
- Vendor
Microsoft
- Vendor
- CVE Published:
- 14 July 2026
What is CVE-2026-57096?
A heap-based buffer overflow exists in the Windows Routing and Remote Access Service (RRAS), which can be exploited by an authorized attacker to escalate privileges on the local system. The vulnerability arises from improper memory management and can potentially allow an attacker to execute arbitrary code with elevated privileges, greatly compromising system security. Microsoft has issued advisories regarding this vulnerability, and it is vital for users to implement the recommended patches promptly to mitigate risks.
Affected Version(s)
Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.9339
Windows 10 Version 1809 32-bit Systems 10.0.17763.0 < 10.0.17763.9020
Windows 10 Version 21H2 32-bit Systems 10.0.19044.0 < 10.0.19044.7548