
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25173 is an integer overflow/wraparound vulnerability in the Windows Routing and Remote Access Service (RRAS) that allows an authorized, low-privileged attacker to execute arbitrary code over a network. Disclosed on March 10, 2026, as part of Microsoft's Patch Tuesday, it affects a broad range of Windows versions including Windows 10 (1607, 1809, 21H2, 22H2), Windows 11 (23H2, 24H2, 25H2, 26H1), and Windows Server editions (2012, 2012 R2, 2016, 2019, 2022, 2025). It carries a CVSS v3.1 base score of 8.0 (High) (Microsoft MSRC).
The vulnerability is rooted in an integer overflow or wraparound condition (CWE-190) in the RRAS service, which subsequently triggers a heap-based buffer overflow (CWE-122) when processing malformed network input. An attacker with low privileges who can interact with the RRAS service over the network can supply crafted input that causes an arithmetic overflow, leading to an undersized heap allocation and subsequent memory corruption. Exploitation requires user interaction (UI:R) and low privileges (PR:L), limiting the attack surface compared to fully unauthenticated vulnerabilities, but the network attack vector (AV:N) makes it reachable remotely (Microsoft MSRC, Feedly).
Successful exploitation results in remote code execution with the privileges of the affected user, impacting confidentiality, integrity, and availability — all rated High. An attacker who achieves code execution on a Windows system running RRAS could access sensitive data, modify system configurations, or use the compromised host as a pivot point for lateral movement within the network. The broad scope of affected products — spanning consumer Windows 10/11 and multiple Windows Server generations — significantly widens the potential attack surface (Microsoft MSRC).
svchost.exe hosting rasman or remoteaccess), such as cmd.exe, powershell.exe, wscript.exe, or network utilities like curl, wget, or certutil.%SystemRoot%\System32\) by the RRAS service account; presence of unexpected scripts, executables, or web shells dropped post-exploitation.HKLM\SYSTEM\CurrentControlSet\Services\RemoteAccess or HKLM\SYSTEM\CurrentControlSet\Services\RasMan.Microsoft released patches on March 10, 2026 as part of Patch Tuesday, with minimum fixed versions as follows: Windows 10 1607/Server 2016 → 10.0.14393.8957; Windows 10 1809/Server 2019 → 10.0.17763.8511; Windows 10 21H2 → 10.0.19044.7058; Windows 10 22H2 → 10.0.19045.7058; Windows 11 23H2 → 10.0.22631.6783; Windows 11 24H2 → 10.0.26100.7979; Windows 11 25H2 → 10.0.26200.7979; Windows 11 26H1 → 10.0.28000.1719; Server 2012 → 6.2.9200.25973; Server 2012 R2 → 6.3.9600.23074; Server 2022 → 10.0.20348.4830; Server 2022 23H2 → 10.0.25398.2207; Server 2025 → 10.0.26100.32463. Microsoft additionally released an out-of-band hotpatch (KB5084597) for Windows 11 24H2/25H2 managed devices to accelerate remediation. As a workaround where patching is not immediately possible, restrict RRAS service access to authorized users only, apply network-level controls to limit exposure of RRAS ports, and apply the principle of least privilege to RRAS service accounts (Microsoft MSRC, BleepingComputer).
The vulnerability received notable coverage following Microsoft's March 2026 Patch Tuesday, with security outlets including BleepingComputer, Rapid7, Sophos, and Computerworld reporting on the RRAS RCE flaws and the subsequent out-of-band hotpatch release (BleepingComputer, Rapid7). The Zero Day Initiative (ZDI) included it in their March 2026 Security Update Review (ZDI). The issuance of an emergency out-of-band hotpatch for Windows 11 enterprise managed devices drew particular attention, signaling Microsoft's concern about exploitation risk. Community discussion on Reddit and security forums highlighted the urgency of patching given the active exploitation reports.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."