CVE-2025-26672
CVSS 3.1 Score 6.5 of 10 (medium)
Details
Summary
CVE-2025-26672 is a buffer over-read vulnerability affecting Microsoft's Windows Routing and Remote Access Service (RRAS). An attacker, without legitimate access, can exploit this issue to disclose sensitive information over a network. The flaw occurs due to the RRAS component mishandling specially crafted packets, leading to unintended memory behavior and potential information leakage. Successful exploitation of this vulnerability may put networks at risk for unauthorized data access or further attacks. Users are recommended to apply the available patch as soon as possible to mitigate this issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Microsoft Windows 10
- Microsoft Windows 11
- Microsoft Windows Server 2008 R2
- Microsoft Windows Server 2022
Affected Vendors
- Microsoft