Severity
8.0HIGH
EPSS
0.1%
top 76.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 10
Latest updateMar 14

Description

Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:HExploitability: 2.1 | Impact: 5.9

Affected Packages29 packages

NVDmicrosoft/windows< 10.0.14393.8957+5
NVDmicrosoft/windows_10_1607< 10.0.14393.8957
NVDmicrosoft/windows_10_1809< 10.0.17763.8511
NVDmicrosoft/windows_10_21h2< 10.0.19044.7058
NVDmicrosoft/windows_10_22h2< 10.0.19045.7058

🔴Vulnerability Details

2
CVEList
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability2026-03-10
GHSA
GHSA-c4cg-7gc9-f4jx: Integer overflow or wraparound in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to execute code over a network2026-03-10

📋Vendor Advisories

1
Microsoft
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability2026-03-10

🕵️Threat Intelligence

2
Bleepingcomputer
Microsoft releases Windows 11 OOB hotpatch to fix RRAS RCE flaw2026-03-14
Wiz
CVE-2026-25173 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-25173 (HIGH CVSS 8) | Integer overflow or wraparound in W | cvebase.io