Junglewise Threat Intelligence

CVE-2026-71353: Microsoft Windows Routing and Remote Access Service double free elevation of privilege

CVE-2026-71353 · Severity: high · CVSS 7 · Published 2026-09-08

Executive brief

Windows Routing and Remote Access Service (RRAS) is a core Windows component that enables remote network connectivity and routing functionality. An attacker with local system access could exploit a double-free memory corruption vulnerability to run code with elevated privileges, potentially gaining complete control over the affected system.

Technical details

A double-free vulnerability exists in the Windows Routing and Remote Access Service (RRAS), where memory is freed twice during processing, leading to heap corruption. The vulnerability requires the attacker to have local access and authorization on the system. Exploitation allows an authenticated attacker to achieve privilege escalation from a lower-privilege context to SYSTEM-level access. This is a memory safety issue in a privileged service component. Microsoft has released patches to address this vulnerability.

Affected products

  • Microsoft Windows Routing and Remote Access Service

Timeline

  • 2026-09-08: disclosed

References