Junglewise Threat Intelligence

CVE-2026-72939: Windows Routing and Remote Access Service null pointer dereference

CVE-2026-72939 · Severity: medium · CVSS 6.5 · Published 2026-09-08

Executive brief

Windows Routing and Remote Access Service (RRAS) is a Microsoft networking component that enables remote access and routing capabilities for corporate networks. A null pointer dereference vulnerability allows an authorized attacker to crash the RRAS service, disrupting remote access and network routing functionality for connected users and devices.

Technical details

A null pointer dereference vulnerability exists in Windows RRAS due to improper input validation in the service's network packet handling logic. The vulnerability requires the attacker to be authenticated or have network access to the RRAS service. When exploited, an attacker can send a specially crafted network request that causes the service to dereference a null pointer, resulting in a denial-of-service condition. The RRAS service will crash, terminating all active remote access sessions and halting routing operations until the service is manually restarted.

Affected products

  • Microsoft Windows <UNKNOWN>

Timeline

  • 2026-09-08: disclosed

References

Related threats