CVE-2025-53138Use of Uninitialized Resource in Microsoft Windows Server 2008 R2 Service Pack 1

Severity
5.7MEDIUMNVD
EPSS
0.3%
top 49.43%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 12

Description

Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:NExploitability: 2.1 | Impact: 3.6

Affected Packages9 packages

CVEListV5microsoft/windows_server_2008_service_pack_26.0.6003.06.0.6003.23471
CVEListV5microsoft/windows_server_2008_r2_service_pack_16.1.7601.06.1.7601.27872
NVDmicrosoft/windows< 10.0.14393.8330+5
CVEListV5microsoft/windows_server_20126.2.9200.06.2.9200.25622
CVEListV5microsoft/windows_server_201610.0.14393.010.0.14393.8330

🔴Vulnerability Details

2
GHSA
GHSA-78g7-jm5h-pv8q: Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network2025-08-12
CVEList
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability2025-08-12

📋Vendor Advisories

2
Microsoft
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability2025-08-12
Microsoft
net/mlx5e: kTLS, Fix incorrect page refcounting2024-12-10
CVE-2025-53138 — Use of Uninitialized Resource | cvebase