cbcvebase.
CVE-2025-21208
published 2025-02-11

CVE-2025-21208: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability

Affected

25 ranges
VendorProductVersion rangeFixed in
microsoftwindows_server_2008
microsoftwindows_server_2008_r2_service_pack_1>= 6.1.7601.0 < 6.1.7601.275666.1.7601.27566
microsoftwindows_server_2008_service_pack_2>= 6.0.6003.0 < 6.0.6003.231176.0.6003.23117
microsoftwindows_server_2012
microsoftwindows_server_2012>= 6.2.9200.0 < 6.2.9200.253176.2.9200.25317
microsoftwindows_server_2012_r2>= 6.3.9600.0 < 6.3.9600.224176.3.9600.22417
microsoftwindows_server_2016< 10.0.14393.778510.0.14393.7785
microsoftwindows_server_2016>= 10.0.14393.0 < 10.0.14393.778510.0.14393.7785
microsoftwindows_server_2019< 10.0.17763.689310.0.17763.6893
microsoftwindows_server_2019>= 10.0.17763.0 < 10.0.17763.689310.0.17763.6893
microsoftwindows_server_2022< 10.0.20348.320710.0.20348.3207
microsoftwindows_server_2022>= 10.0.20348.0 < 10.0.20348.320710.0.20348.3207
microsoftwindows_server_2022_23h2< 10.0.25398.142510.0.25398.1425
microsoftwindows_server_2025< 10.0.26100.319410.0.26100.3194
microsoftwindows_server_2025>= 10.0.26100.0 < 10.0.26100.319410.0.26100.3194
msrcwindows_server_2008_for_32-bit_systems_service_pack_2
msrcwindows_server_2008_for_x64-based_systems_service_pack_2
msrcwindows_server_2008_r2_for_x64-based_systems_service_pack_1
msrcwindows_server_2012
msrcwindows_server_2012_r2
msrcwindows_server_2016
msrcwindows_server_2019
msrcwindows_server_2022
msrcwindows_server_2022_23h2_edition
msrcwindows_server_2025