CVE-2024-26205

CVSS 3.1 Score 8.8 of 10 (high)

Details

Published Apr 9, 2024
Updated: Jan 8, 2025
CWE ID 122

Summary

CVE-2024-26205 is a newly disclosed remote code execution vulnerability affecting Microsoft's Routing and Remote Access Service (RRAS) in Windows. An attacker can exploit this vulnerability by sending specially crafted packets to a targeted RRAS server, resulting in arbitrary code execution on the system. Successful exploitation could allow the attacker to install programs, view, change, or delete data, or create new accounts with full user rights. Organizations using RRAS should apply the forthcoming Microsoft patch as soon as it becomes available to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share