CVE-2026-25172
vulnerability analysis and mitigation

Overview

CVE-2026-25172 is an integer overflow/wraparound vulnerability in the Windows Routing and Remote Access Service (RRAS) that allows network-based attackers to execute arbitrary code remotely. Disclosed on March 10, 2026, as part of Microsoft's Patch Tuesday, it affects a wide range of Windows versions including Windows 10 (multiple builds), Windows 11 (multiple builds), and Windows Server 2012 through 2025. The vulnerability carries a CVSS v3.1 base score of 8.0 (High) per Microsoft's advisory, though ENISA rates it at 8.8 (Microsoft MSRC, Feedly).

Technical details

The root cause is an integer overflow or wraparound (CWE-190) in the RRAS component that leads to a heap-based buffer overflow condition (CWE-122). When an attacker-controlled RRAS server sends maliciously crafted data to a domain-joined client, improper integer arithmetic causes a buffer overflow in heap memory, enabling arbitrary code execution. Exploitation requires low-privilege authentication and minimal user interaction (the victim must connect to a malicious RRAS server), making it a network-reachable attack with low complexity (Microsoft MSRC, Feedly).

Impact

Successful exploitation results in complete system compromise with high impact to confidentiality, integrity, and availability — attackers can execute arbitrary code in the context of the RRAS service. The attack scenario primarily targets domain-joined systems connecting to malicious RRAS servers, enabling lateral movement across domain environments. The broad scope of affected Windows versions (Server 2012 through 2025, Windows 10/11 across multiple builds) significantly expands the potential attack surface (Feedly).

Exploitation steps

  1. Reconnaissance: Identify domain-joined Windows systems running RRAS clients using network scanning tools (e.g., Nmap, Shodan) or Active Directory enumeration. Target systems running unpatched Windows versions prior to the March 2026 patch.
  2. Set up malicious RRAS server: Deploy a rogue RRAS server on an attacker-controlled host within network reach of the target, configured to respond to VPN or dial-up connection requests.
  3. Induce victim connection: Use social engineering, DNS poisoning, or network-level manipulation (e.g., ARP spoofing, rogue DHCP) to cause a domain-joined client to connect to the malicious RRAS server.
  4. Trigger integer overflow: Send a specially crafted RRAS protocol response containing malformed data that causes an integer overflow in the client-side RRAS processing code, resulting in a heap-based buffer overflow.
  5. Achieve code execution: The heap overflow overwrites critical memory structures, redirecting execution flow to attacker-controlled shellcode or ROP chain, achieving remote code execution on the victim system.
  6. Lateral movement: Use the compromised system as a pivot point to move laterally across the domain environment, leveraging domain credentials or tokens accessible from the compromised RRAS client (Feedly, onsec.io blog).

Indicators of compromise

  • Network: Unexpected outbound VPN or RRAS connection attempts from workstations or servers to unknown/external IP addresses; unusual PPTP (TCP 1723), L2TP (UDP 1701), or SSTP (TCP 443) traffic to non-corporate endpoints.
  • Network: Connections to newly registered or low-reputation IP addresses over RRAS-associated ports shortly before anomalous process activity.
  • Logs: Windows Event Log entries (Event ID 20227, 20228) showing RRAS connection failures or unexpected successful connections to unfamiliar servers; RasClient errors in the Application log.
  • Logs: Crash dumps or Windows Error Reporting (WER) entries related to svchost.exe hosting the RRAS service (rasman.dll, rasapi32.dll) indicating heap corruption.
  • Process: Unusual child processes spawned by svchost.exe (RRAS service host) such as cmd.exe, powershell.exe, mshta.exe, or network utilities (curl, certutil).
  • File System: Unexpected files written to %SystemRoot%\System32\ or temp directories by the RRAS service account; new scheduled tasks or services created post-connection.
  • Registry: New or modified registry keys under HKLM\SYSTEM\CurrentControlSet\Services\RemoteAccess or HKLM\SYSTEM\CurrentControlSet\Services\RasMan indicating configuration tampering (Feedly).

Mitigation and workarounds

Microsoft released patches on March 10, 2026 (Patch Tuesday) addressing this vulnerability across all affected platforms. Key patched build numbers include: Windows Server 2022 → 10.0.20348.4830 or later; Windows Server 2022 23H2 → 10.0.25398.2207 or later; Windows Server 2025 → 10.0.26100.32463 or later; Windows Server 2019 → 10.0.17763.8511 or later; Windows Server 2016 → 10.0.14393.8957 or later; Windows Server 2012/2012 R2 → 6.2.9200.25973 / 6.3.9600.23074 or later. An additional out-of-band hotpatch (KB5084597) was released on March 14–15, 2026 specifically for Windows 11 (24H2/25H2) managed devices. As a workaround where patching is not immediately possible, disable RRAS on systems that do not require it, implement network segmentation to restrict RRAS traffic, and monitor for suspicious RRAS connection attempts (Microsoft MSRC, BleepingComputer).

Community reactions

The vulnerability received significant coverage following Microsoft's March 2026 Patch Tuesday, with security outlets including BleepingComputer, Rapid7, Sophos, and Zero Day Initiative (ZDI) highlighting it among the notable fixes. Microsoft's decision to issue an out-of-band hotpatch (KB5084597) for Windows 11 just days after Patch Tuesday signaled elevated urgency, drawing attention from the community on Reddit (r/pwnhub) and tech media including Computerworld, Neowin, and Heise. AhnLab ASEC and onsec.io reported on exploitation activity in the wild, elevating community concern. The Qualys scanner team added detection (ID 92365) shortly after disclosure, reflecting rapid industry response (BleepingComputer, ZDI Blog, onsec.io blog).

Additional resources


SourceThis report was generated using AI

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management