CVE-2025-21208
published 2025-02-11CVE-2025-21208: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
PriorityP356high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
1.92%
77.6th percentile
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Affected
25 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2008_r2_service_pack_1 | >= 6.1.7601.0 < 6.1.7601.27566 | 6.1.7601.27566 |
| microsoft | windows_server_2008_service_pack_2 | >= 6.0.6003.0 < 6.0.6003.23117 | 6.0.6003.23117 |
| microsoft | windows_server_2012 | — | — |
| microsoft | windows_server_2012 | >= 6.2.9200.0 < 6.2.9200.25317 | 6.2.9200.25317 |
| microsoft | windows_server_2012_r2 | >= 6.3.9600.0 < 6.3.9600.22417 | 6.3.9600.22417 |
| microsoft | windows_server_2016 | < 10.0.14393.7785 | 10.0.14393.7785 |
| microsoft | windows_server_2016 | >= 10.0.14393.0 < 10.0.14393.7785 | 10.0.14393.7785 |
| microsoft | windows_server_2019 | < 10.0.17763.6893 | 10.0.17763.6893 |
| microsoft | windows_server_2019 | >= 10.0.17763.0 < 10.0.17763.6893 | 10.0.17763.6893 |
| microsoft | windows_server_2022 | < 10.0.20348.3207 | 10.0.20348.3207 |
| microsoft | windows_server_2022 | >= 10.0.20348.0 < 10.0.20348.3207 | 10.0.20348.3207 |
| microsoft | windows_server_2022_23h2 | < 10.0.25398.1425 | 10.0.25398.1425 |
| microsoft | windows_server_2025 | < 10.0.26100.3194 | 10.0.26100.3194 |
| microsoft | windows_server_2025 | >= 10.0.26100.0 < 10.0.26100.3194 | 10.0.26100.3194 |
| msrc | windows_server_2008_for_32-bit_systems_service_pack_2 | — | — |
| msrc | windows_server_2008_for_x64-based_systems_service_pack_2 | — | — |
| msrc | windows_server_2008_r2_for_x64-based_systems_service_pack_1 | — | — |
| msrc | windows_server_2012 | — | — |
| msrc | windows_server_2012_r2 | — | — |
| msrc | windows_server_2016 | — | — |
| msrc | windows_server_2019 | — | — |
| msrc | windows_server_2022 | — | — |
| msrc | windows_server_2022_23h2_edition | — | — |
| msrc | windows_server_2025 | — | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2f84-gmq2-v8m2: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
ghsa_unreviewed·2025-02-11
CVE-2025-21208 [HIGH] CWE-122 GHSA-2f84-gmq2-v8m2: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Microsoft
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
vendor_msrc·2025-02-11·CVSS 8.8
CVE-2025-21208 [HIGH] CWE-122 Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
FAQ: How could an attacker exploit this vulnerability?
An attacker could exploit this vulnerability by tricking a user into sending a request to a malicious server. This could result in the server returning malicious data that might cause arbitrary code execution on the user's system.
FAQ: According to the CVSS metric, the attack vector is network (AV:N) and the user interaction is required (UI:R). What is the target context of the remote code execution?
This attack requires an admin user on the client to connect to a malicious server, and that could allow the attacker to gain code execution on the client.
Windows Routing and Remote Access Service (RRAS): Windows Routing and Remote Access Service (RRAS)
No detection rules found.
No public exploits indexed.
Talos
Microsoft Patch Tuesday for February 2025 — Snort rules and prominent vulnerabilities
blogs_talos·2025-02-11·CVSS 8.7
CVE-2025-21376 [HIGH] Microsoft Patch Tuesday for February 2025 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for February of 2025 which includes 63 vulnerabilities affecting a range of products, including 4 that Microsoft marked as “critical” and one marked as "moderate."
There are two notable "critical" vulnerabilities. The first is CVE-2025-21376, which is a remote code execution (RCE) vulnerability affecting the Windows Lightweight Directory Access Protocol (LDAP). This vulnerability is a remote unauthenticated Out-of-bounds Write (OOBW) caused by a race condition in LDAP and could potentially result in arbitrary code execution in the Local Security Authority Subsystem Service (lsass.exe). This is a process in the Microsoft Windows operating systems that is responsible for enforcing the security policy on the system. Successful exploitation o
Talos
Microsoft Patch Tuesday for February 2025 — Snort rules and prominent vulnerabilities
blogs_talos·2025-02-11·CVSS 8.7
CVE-2025-21376 [HIGH] Microsoft Patch Tuesday for February 2025 — Snort rules and prominent vulnerabilities
## Microsoft Patch Tuesday for February 2025 — Snort rules and prominent vulnerabilities
Microsoft has released its monthly security update for February of 2025 which includes 63 vulnerabilities affecting a range of products, including 4 that Microsoft marked as “critical” and one marked as "moderate."
There are two notable "critical" vulnerabilities. The first is CVE-2025-21376 , which is a remote code execution (RCE) vulnerability affecting the Windows Lightweight Directory Access Protocol (LDAP). This vulnerability is a remote unauthenticated Out-of-bounds Write (OOBW) caused by a race condition in LDAP and could potentially result in arbitrary code execution in the Local Security Authority Subsystem Service (lsass.exe). This is a process in the Microsoft Windows operating systems tha
Bleepingcomputer
Microsoft February 2025 Patch Tuesday fixes 4 zero-days, 55 flaws
blogs_bleepingcomputer·2025-02-11·CVSS 7.1
[HIGH] Microsoft February 2025 Patch Tuesday fixes 4 zero-days, 55 flaws
## Microsoft February 2025 Patch Tuesday fixes 4 zero-days, 55 flaws
## Lawrence Abrams
19 Elevation of Privilege Vulnerabilities
2 Security Feature Bypass Vulnerabilities
22 Remote Code Execution Vulnerabilities
1 Information Disclosure Vulnerabilities
9 Denial of Service Vulnerabilities
3 Spoofing Vulnerabilities
The above numbers do not include a critical Microsoft Dynamics 365 Sales elevation of privileges flaw and 10 Microsoft Edge vulnerabilities fixed on February 6.
To learn more about the non-security updates released today, you can review our dedicated articles on the Windows 11 KB5051987 & KB5051989 cumulative updates and the Windows 10 KB5051974 update .
## Two actively exploited zero-day disclosed
This month's Patch Tuesday fixes two actively exploited and two public
2025-02-11
Published