cbcvebase.
CVE-2025-60713
published 2025-11-11

CVE-2025-60713: Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
Untrusted pointer dereference in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

Affected

14 ranges
VendorProductVersion rangeFixed in
microsoftwindows_server_2016< 10.0.14393.859410.0.14393.8594
microsoftwindows_server_2016>= 10.0.14393.0 < 10.0.14393.859410.0.14393.8594
microsoftwindows_server_2019< 10.0.17763.802710.0.17763.8027
microsoftwindows_server_2019>= 10.0.17763.0 < 10.0.17763.802710.0.17763.8027
microsoftwindows_server_2022< 10.0.20348.434610.0.20348.4346
microsoftwindows_server_2022>= 10.0.20348.0 < 10.0.20348.440510.0.20348.4405
microsoftwindows_server_2022_23h2< 10.0.25398.196510.0.25398.1965
microsoftwindows_server_2025< 10.0.26100.709210.0.26100.7092
microsoftwindows_server_2025>= 10.0.26100.0 < 10.0.26100.717110.0.26100.7171
msrcwindows_server_2016
msrcwindows_server_2019
msrcwindows_server_2022
msrcwindows_server_2022_23h2_edition
msrcwindows_server_2025