PT-2026-24300 · Microsoft · Windows

Published

2026-03-10

·

Updated

2026-03-23

·

CVE-2026-25173

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Windows Routing and Remote Access Service (RRAS) (affected versions not specified)
Description An integer overflow or wraparound issue exists in Windows Routing and Remote Access Service (RRAS). This can allow an authorized attacker to execute code over a network. The issue involves a buffer overflow in memory. Exploitation may allow a remote attacker to execute arbitrary code.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Heap Based Buffer Overflow

Integer Overflow

Weakness Enumeration

Related Identifiers

BDU:2026-02972
CVE-2026-25173

Affected Products

Windows