CVE-2025-64678
vulnerability analysis and mitigation

Overview

CVE-2025-64678 is a heap-based buffer overflow vulnerability in the Windows Routing and Remote Access Service (RRAS) that allows an unauthorized attacker to execute arbitrary code over a network. It was disclosed and patched on December 9, 2025, as part of Microsoft's December 2025 Patch Tuesday security update. The vulnerability affects a wide range of Microsoft Windows versions, including Windows Server 2008 through 2025 and Windows 10/11 (multiple feature update versions). It carries a CVSS v3.1 base score of 8.8 (High), requiring user interaction but no privileges (Microsoft MSRC).

Technical details

The vulnerability is classified as CWE-122 (Heap-based Buffer Overflow), occurring within the Windows RRAS service when processing maliciously crafted network data. According to available intelligence, an attacker authenticated on a domain can exploit this by tricking domain-joined users into sending requests to a malicious server via the RRAS Snap-in; the malicious server returns crafted data that triggers the heap overflow, resulting in code execution on the victim's system. The attack vector is network-based with low complexity, but requires user interaction (UI:R), meaning a victim must be induced to connect to or interact with an attacker-controlled server. No public proof-of-concept exploit code has been identified at this time (Microsoft MSRC, Feedly).

Impact

Successful exploitation results in high impact to confidentiality, integrity, and availability — an attacker can achieve arbitrary remote code execution on the affected Windows system. This could enable full system compromise, credential theft, installation of malware or backdoors, and lateral movement within domain environments. Given the breadth of affected products spanning Windows Server 2008 through 2025 and multiple Windows 10/11 versions, the potential attack surface is significant for enterprise environments (Microsoft MSRC).

Exploitation steps

  1. Reconnaissance: Identify target Windows systems running RRAS (Routing and Remote Access Service) within a domain environment, focusing on systems where users may use the RRAS Snap-in for management.
  2. Setup malicious server: Deploy an attacker-controlled server that mimics a legitimate RRAS endpoint and is configured to return specially crafted, malformed response data designed to trigger a heap buffer overflow in the RRAS client-side processing.
  3. Social engineering / phishing: Trick a domain-joined user (e.g., a network administrator) into connecting to the malicious server via the RRAS Snap-in, such as through a phishing email, malicious link, or by poisoning network discovery mechanisms.
  4. Trigger the overflow: When the victim's system processes the malicious server response, the heap-based buffer overflow is triggered in the RRAS service, corrupting heap memory.
  5. Achieve code execution: By controlling the overflow data, the attacker overwrites heap metadata or function pointers to redirect execution flow, achieving arbitrary code execution in the context of the RRAS service on the victim's machine (Microsoft MSRC).

Indicators of compromise

  • Network: Unusual outbound connections from Windows systems to unknown or external RRAS/VPN endpoints; unexpected RRAS Snap-in connections to non-standard server addresses.
  • Logs: Windows Event Log entries showing RRAS service crashes or unexpected restarts (Event IDs related to service failures in System log); error entries in the RemoteAccess event log channel around the time of exploitation.
  • Process: Unexpected child processes spawned by the RRAS service (svchost.exe hosting rasman or remoteaccess), such as cmd.exe, powershell.exe, or network utilities.
  • File System: New or modified files in system directories created by the RRAS service account; unexpected scheduled tasks or services installed post-exploitation.

Mitigation and workarounds

Microsoft released security updates on December 9, 2025 addressing this vulnerability across all affected platforms. Key patched build versions include: Windows 10 1607/Server 2016 (10.0.14393.8594), Windows 10 1809/Server 2019 (10.0.17763.8027), Windows 10 21H2 (10.0.19044.6575), Windows 10 22H2 (10.0.19045.6575), Windows 11 23H2 (10.0.22631.6199), Windows 11 24H2/Server 2025 (10.0.26100.7092), Windows 11 25H2 (10.0.26200.7092), and Windows Server 2022 23H2 (10.0.25398.1965). Organizations should apply the December 2025 Patch Tuesday updates immediately, prioritizing internet-facing and domain-critical systems. As a defense-in-depth measure, restrict access to RRAS services using network segmentation and firewall rules, and monitor for suspicious RRAS activity (Microsoft MSRC).

Community reactions

The vulnerability was covered as part of broader December 2025 Patch Tuesday reporting by multiple security outlets. BleepingComputer noted it among 57 flaws fixed in the December 2025 update, which also included 3 zero-days (BleepingComputer). Zero Day Initiative (ZDI) included it in their December 2025 security update review (ZDI Blog). Sophos and SANS ISC also published Patch Tuesday roundups covering this vulnerability. No specific researcher commentary or significant social media discussion focused exclusively on CVE-2025-64678 has been identified, consistent with the absence of a public PoC or active exploitation.

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management