Junglewise Threat Intelligence

CVE-2026-57096: Microsoft Windows RRAS heap overflow privilege escalation

CVE-2026-57096 · Severity: high · CVSS 7.8 · Published 2026-07-14

Technologies: Microsoft Windows Server 2012 R2, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in the Windows Routing and Remote Access Service (RRAS), a component used to provide connectivity for remote users and site-to-site connections. An attacker who already has basic access to a computer could exploit this flaw to gain full administrative control over the system. This could allow them to access sensitive data, install malicious software, or disrupt business operations.

Technical details

A heap-based buffer overflow vulnerability (CWE-122) exists in the Microsoft Windows Routing and Remote Access Service (RRAS). The flaw is triggered when the service improperly handles memory allocation in the heap, allowing an attacker to overwrite adjacent memory. To exploit this, an attacker must first have local access to the target system with low-level user privileges. Successful exploitation allows the attacker to execute arbitrary code with elevated system privileges. Microsoft has released security updates to address this issue across multiple versions of Windows and Windows Server.

Affected products

  • Microsoft Windows 10 Versions 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 Versions 24H2, 25H2, 26H1
  • Microsoft Windows Server 2012 R2 All installations

Timeline

  • 2026-07-14: advisory: Initial disclosure by Microsoft and NVD
  • 2026-07-14: patched: Security updates released by Microsoft

References

Related threats