Severity
8.0HIGH
EPSS
0.1%
top 76.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 10
Latest updateMar 14

Description

Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:HExploitability: 2.1 | Impact: 5.9

Affected Packages21 packages

NVDmicrosoft/windows< 10.0.14393.8957+5
CVEListV5microsoft/windows_server_20126.2.9200.06.2.9200.25973
CVEListV5microsoft/windows_server_201610.0.14393.010.0.14393.8957
CVEListV5microsoft/windows_server_201910.0.17763.010.0.17763.8511
CVEListV5microsoft/windows_server_202210.0.20348.010.0.20348.4893

🔴Vulnerability Details

2
CVEList
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability2026-03-10
GHSA
GHSA-h7qm-f9j7-jr28: Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network2026-03-10

📋Vendor Advisories

1
Microsoft
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability2026-03-10

🕵️Threat Intelligence

2
Bleepingcomputer
Microsoft releases Windows 11 OOB hotpatch to fix RRAS RCE flaw2026-03-14
Wiz
CVE-2026-25172 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-25172 (HIGH CVSS 8) | Integer overflow or wraparound in W | cvebase.io