Executive brief
Windows Routing and Remote Access Service (RRAS) is a core Windows component that enables remote network connectivity and VPN functionality for enterprise environments. A remote code execution vulnerability in RRAS allows unauthenticated network attackers to execute arbitrary code with system-level privileges, potentially leading to full compromise of affected servers and lateral movement within corporate networks.
Technical details
This vulnerability is a remote code execution flaw in the Windows Routing and Remote Access Service (RRAS) component. The vulnerability is network-accessible and does not require authentication or user interaction to exploit. Successful exploitation allows an attacker to execute arbitrary code with SYSTEM privileges on the affected machine. While specific root cause details are not available in the advisory, the attack vector and severity indicate a critical network-facing service flaw. Microsoft has issued security updates through its standard patch cycle.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed