Junglewise Threat Intelligence

CVE-2026-71351: Microsoft Windows RRAS double free vulnerability

CVE-2026-71351 · Severity: high · CVSS 7 · Published 2026-09-08

Executive brief

Windows Routing and Remote Access Service (RRAS) is a critical component that enables secure remote access and routing for corporate networks and servers. A double free memory vulnerability in RRAS allows an authorized user with local access to crash the service or execute arbitrary code with elevated system privileges, potentially compromising the entire server or network infrastructure.

Technical details

A double free vulnerability exists in the Windows Routing and Remote Access Service (RRAS), which occurs when memory is freed twice, leading to heap corruption. The vulnerability can be exploited by an authorized attacker with local access to elevate privileges. The attack requires that the attacker already has local system access or valid credentials. Successful exploitation could result in arbitrary code execution with SYSTEM privileges. A patch is expected from Microsoft as part of their regular security update cycle.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats