cbcvebase.
CVE-2025-26667
published 2025-04-08

CVE-2025-26667: Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose…

medium6.5CVSS 3.1
AVNACLPRNUIRSUCHINAN
Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.

Affected

25 ranges
VendorProductVersion rangeFixed in
microsoftwindows_server_2008
microsoftwindows_server_2008_r2_service_pack_1>= 6.1.7601.0 < 6.1.7601.276706.1.7601.27670
microsoftwindows_server_2008_service_pack_2>= 6.0.6003.0 < 6.0.6003.232206.0.6003.23220
microsoftwindows_server_2012
microsoftwindows_server_2012>= 6.2.9200.0 < 6.2.9200.254236.2.9200.25423
microsoftwindows_server_2012_r2>= 6.3.9600.0 < 6.3.9600.225236.3.9600.22523
microsoftwindows_server_2016< 10.0.14393.796910.0.14393.7969
microsoftwindows_server_2016>= 10.0.14393.0 < 10.0.14393.796910.0.14393.7969
microsoftwindows_server_2019< 10.0.17763.713610.0.17763.7136
microsoftwindows_server_2019>= 10.0.17763.0 < 10.0.17763.713610.0.17763.7136
microsoftwindows_server_2022< 10.0.20348.345310.0.20348.3453
microsoftwindows_server_2022>= 10.0.20348.0 < 10.0.20348.345310.0.20348.3453
microsoftwindows_server_2022_23h2< 10.0.25398.155110.0.25398.1551
microsoftwindows_server_2025< 10.0.26100.377510.0.26100.3775
microsoftwindows_server_2025>= 10.0.26100.0 < 10.0.26100.377510.0.26100.3775
msrcwindows_server_2008_for_32-bit_systems_service_pack_2
msrcwindows_server_2008_for_x64-based_systems_service_pack_2
msrcwindows_server_2008_r2_for_x64-based_systems_service_pack_1
msrcwindows_server_2012
msrcwindows_server_2012_r2
msrcwindows_server_2016
msrcwindows_server_2019
msrcwindows_server_2022
msrcwindows_server_2022_23h2_edition
msrcwindows_server_2025