CVE-2024-26179

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Apr 9, 2024
Updated: Jan 8, 2025
CWE ID 122

Summary

CVE-2024-26179 is a newly disclosed remote code execution vulnerability affecting Microsoft's Windows Routing and Remote Access Service (RRAS). Malicious actors can exploit this weakness by sending specially crafted RRAS packets to target systems, resulting in unauthorized code execution. Successful exploitation could allow an attacker to gain full control over the compromised system, potentially leading to data theft or further network compromise. It is recommended that affected organizations apply the upcoming Microsoft patch as soon as it becomes available to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share