Executive brief
A security vulnerability has been identified in the Windows Routing and Remote Access Service (RRAS), a component used to provide routing and VPN services. An attacker could exploit this flaw over the network to gain unauthorized control of the affected system. This could lead to a complete compromise of the server, including data theft or service disruption. Organizations should apply the latest Windows security updates to mitigate this risk.
Technical details
A heap-based buffer overflow (CWE-122) exists in the Microsoft Windows Routing and Remote Access Service (RRAS). The vulnerability is reachable over the network and does not require administrative privileges, though the CVSS vector suggests some level of user interaction may be required (UI:R). Successful exploitation allows for remote code execution (RCE) in the context of the service. Affected versions include various releases of Windows 10, Windows 11, and Windows Server 2008 R2. Microsoft has released security updates to address this issue, and administrators are advised to verify their build versions against the patched releases (e.g., 10.0.19045.6809 for Windows 10 22H2).
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 22H3, 23H2, 24H2, 25H2
- Microsoft Windows Server 2008 R2 Service Pack 1
Timeline
- 2026-01-13: disclosed: Initial NVD publication date
- 2026-07-30: patched: Microsoft updated the advisory with specific version information
References
- https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-20868
- https://www.vicarius.io/vsociety/posts/cve-2026-20868-detection-script-heap-based-buffer-overflow-vulnerability-affecting-windows-rras
- https://www.vicarius.io/vsociety/posts/cve-2026-20868-mitigation-script-heap-based-buffer-overflow-vulnerability-affecting-windows-rras