Executive brief
Windows RRAS is a Microsoft networking service that allows remote users to connect to corporate networks. A remote code execution vulnerability in this service allows unauthenticated attackers to execute arbitrary code and gain unauthorized access to affected systems, potentially compromising network security and enabling lateral movement within an organization.
Technical details
This is a remote code execution vulnerability in Windows Routing and Remote Access Service (RRAS). The vulnerability allows an attacker with network access to the RRAS interface to execute arbitrary code on the affected system without authentication. Successful exploitation grants an attacker complete control over the compromised system. This is a network-reachable vulnerability with no authentication required, making it a particularly high-risk issue for systems exposed to untrusted networks. Microsoft has issued patches for affected Windows versions.
Affected products
- Microsoft Windows RRAS <UNKNOWN>
Timeline
- 2026-09-08: disclosed