
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25172 is an integer overflow/wraparound vulnerability in the Windows Routing and Remote Access Service (RRAS) that allows network-based attackers to execute arbitrary code remotely. Disclosed on March 10, 2026, as part of Microsoft's Patch Tuesday, it affects a wide range of Windows versions including Windows 10 (multiple builds), Windows 11 (multiple builds), and Windows Server 2012 through 2025. The vulnerability carries a CVSS v3.1 base score of 8.0 (High) per Microsoft's advisory, though ENISA rates it at 8.8 (Microsoft MSRC, Feedly).
The root cause is an integer overflow or wraparound (CWE-190) in the RRAS component that leads to a heap-based buffer overflow condition (CWE-122). When an attacker-controlled RRAS server sends maliciously crafted data to a domain-joined client, improper integer arithmetic causes a buffer overflow in heap memory, enabling arbitrary code execution. Exploitation requires low-privilege authentication and minimal user interaction (the victim must connect to a malicious RRAS server), making it a network-reachable attack with low complexity (Microsoft MSRC, Feedly).
Successful exploitation results in complete system compromise with high impact to confidentiality, integrity, and availability — attackers can execute arbitrary code in the context of the RRAS service. The attack scenario primarily targets domain-joined systems connecting to malicious RRAS servers, enabling lateral movement across domain environments. The broad scope of affected Windows versions (Server 2012 through 2025, Windows 10/11 across multiple builds) significantly expands the potential attack surface (Feedly).
svchost.exe hosting the RRAS service (rasman.dll, rasapi32.dll) indicating heap corruption.svchost.exe (RRAS service host) such as cmd.exe, powershell.exe, mshta.exe, or network utilities (curl, certutil).%SystemRoot%\System32\ or temp directories by the RRAS service account; new scheduled tasks or services created post-connection.HKLM\SYSTEM\CurrentControlSet\Services\RemoteAccess or HKLM\SYSTEM\CurrentControlSet\Services\RasMan indicating configuration tampering (Feedly).Microsoft released patches on March 10, 2026 (Patch Tuesday) addressing this vulnerability across all affected platforms. Key patched build numbers include: Windows Server 2022 → 10.0.20348.4830 or later; Windows Server 2022 23H2 → 10.0.25398.2207 or later; Windows Server 2025 → 10.0.26100.32463 or later; Windows Server 2019 → 10.0.17763.8511 or later; Windows Server 2016 → 10.0.14393.8957 or later; Windows Server 2012/2012 R2 → 6.2.9200.25973 / 6.3.9600.23074 or later. An additional out-of-band hotpatch (KB5084597) was released on March 14–15, 2026 specifically for Windows 11 (24H2/25H2) managed devices. As a workaround where patching is not immediately possible, disable RRAS on systems that do not require it, implement network segmentation to restrict RRAS traffic, and monitor for suspicious RRAS connection attempts (Microsoft MSRC, BleepingComputer).
The vulnerability received significant coverage following Microsoft's March 2026 Patch Tuesday, with security outlets including BleepingComputer, Rapid7, Sophos, and Zero Day Initiative (ZDI) highlighting it among the notable fixes. Microsoft's decision to issue an out-of-band hotpatch (KB5084597) for Windows 11 just days after Patch Tuesday signaled elevated urgency, drawing attention from the community on Reddit (r/pwnhub) and tech media including Computerworld, Neowin, and Heise. AhnLab ASEC and onsec.io reported on exploitation activity in the wild, elevating community concern. The Qualys scanner team added detection (ID 92365) shortly after disclosure, reflecting rapid industry response (BleepingComputer, ZDI Blog, onsec.io blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."