PT-2026-2692 · Microsoft · Windows Routing/Remote Access Service+1

Ezrakie

·

Published

2026-01-13

·

Updated

2026-01-14

·

CVE-2026-20843

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Windows Routing and Remote Access Service (RRAS) (affected versions not specified)
Description An issue with access control in Windows Routing and Remote Access Service (RRAS) could allow a local attacker to gain elevated privileges. The vulnerability allows an authorized attacker to elevate privileges locally.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Weakness Enumeration

Related Identifiers

BDU:2026-00385
CVE-2026-20843

Affected Products

Windows
Windows Routing/Remote Access Service