CVE-2025-21203

CVSS 3.1 Score 6.5 of 10 (medium)

Details

Published Apr 8, 2025
Updated: Apr 9, 2025
CWE ID 126

Summary

CVE-2025-21203 is a buffer over-read vulnerability impacting the Windows Routing and Remote Access Service (RRAS). An unauthorized attacker can exploit this issue, causing the software to read past the intended buffer boundary. The consequence of this action is the disclosure of sensitive information over a network, posing a significant risk to security. This vulnerability requires no user interaction and can be triggered remotely. Microsoft has released a patch to address this issue, and it is strongly recommended that affected systems be updated promptly to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows Server 2008 R2
  • Microsoft Windows Server 2022

Affected Vendors

  • Microsoft