PT-2026-24299 · Microsoft · Windows Nt Rras+1

Published

2026-03-10

·

Updated

2026-03-16

·

CVE-2026-25172

CVSS v2.0
10
VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Windows Routing and Remote Access Service (RRAS) (affected versions not specified)
Description An integer overflow or wraparound exists in Windows Routing and Remote Access Service (RRAS), potentially allowing an unauthorized attacker to execute code over a network. This issue enables network-based remote code execution by both unauthorized and authorized users. Three critical bugs have been disclosed, identified as CVE-2026-25172, CVE-2026-25173, and CVE-2026-26111.
Recommendations Versions prior to the March 10, 2026 patch are vulnerable.

Fix

RCE

Integer Overflow

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

BDU:2026-02993
CVE-2026-25172

Affected Products

Windows
Windows Nt Rras