
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-64678 is a heap-based buffer overflow vulnerability in the Windows Routing and Remote Access Service (RRAS) that allows an unauthorized attacker to execute arbitrary code over a network. It was disclosed and patched on December 9, 2025, as part of Microsoft's December 2025 Patch Tuesday security update. The vulnerability affects a wide range of Microsoft Windows versions, including Windows Server 2008 through 2025 and Windows 10/11 (multiple feature update versions). It carries a CVSS v3.1 base score of 8.8 (High), requiring user interaction but no privileges (Microsoft MSRC).
The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow), occurring within the Windows RRAS service when processing maliciously crafted network data. According to available intelligence, an attacker authenticated on a domain can exploit this by tricking domain-joined users into sending requests to a malicious server via the RRAS Snap-in; the malicious server returns crafted data that triggers the heap overflow, resulting in code execution on the victim's system. The attack vector is network-based with low complexity, but requires user interaction (UI:R), meaning a victim must be induced to connect to or interact with an attacker-controlled server. No public proof-of-concept exploit code has been identified at this time (Microsoft MSRC, Feedly).
Successful exploitation results in high impact to confidentiality, integrity, and availability — an attacker can achieve arbitrary remote code execution on the affected Windows system. This could enable full system compromise, credential theft, installation of malware or backdoors, and lateral movement within domain environments. Given the breadth of affected products spanning Windows Server 2008 through 2025 and multiple Windows 10/11 versions, the potential attack surface is significant for enterprise environments (Microsoft MSRC).
svchost.exe hosting rasman or remoteaccess), such as cmd.exe, powershell.exe, or network utilities.Microsoft released security updates on December 9, 2025 addressing this vulnerability across all affected platforms. Key patched build versions include: Windows 10 1607/Server 2016 (10.0.14393.8594), Windows 10 1809/Server 2019 (10.0.17763.8027), Windows 10 21H2 (10.0.19044.6575), Windows 10 22H2 (10.0.19045.6575), Windows 11 23H2 (10.0.22631.6199), Windows 11 24H2/Server 2025 (10.0.26100.7092), Windows 11 25H2 (10.0.26200.7092), and Windows Server 2022 23H2 (10.0.25398.1965). Organizations should apply the December 2025 Patch Tuesday updates immediately, prioritizing internet-facing and domain-critical systems. As a defense-in-depth measure, restrict access to RRAS services using network segmentation and firewall rules, and monitor for suspicious RRAS activity (Microsoft MSRC).
The vulnerability was covered as part of broader December 2025 Patch Tuesday reporting by multiple security outlets. BleepingComputer noted it among 57 flaws fixed in the December 2025 update, which also included 3 zero-days (BleepingComputer). Zero Day Initiative (ZDI) included it in their December 2025 security update review (ZDI Blog). Sophos and SANS ISC also published Patch Tuesday roundups covering this vulnerability. No specific researcher commentary or significant social media discussion focused exclusively on CVE-2025-64678 has been identified, consistent with the absence of a public PoC or active exploitation.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."