Windows Routing and Remote Access Service (RRAS)
by Microsoft
CVEs (114)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-26667 | Med | 0.42 | 6.5 | 0.02 | Apr 8, 2025 | Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-26664 | Med | 0.42 | 6.5 | 0.02 | Apr 8, 2025 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-21203 | Med | 0.42 | 6.5 | 0.01 | Apr 8, 2025 | Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2024-38214 | Med | 0.42 | 6.5 | 0.02 | Aug 13, 2024 | Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability | ||
| CVE-2025-53719 | Med | 0.37 | 5.7 | 0.01 | Aug 12, 2025 | Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. | ||
| CVE-2025-53153 | Med | 0.37 | 5.7 | 0.01 | Aug 12, 2025 | Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. | ||
| CVE-2025-53148 | Med | 0.37 | 5.7 | 0.01 | Aug 12, 2025 | Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. | ||
| CVE-2025-53138 | Med | 0.37 | 5.7 | 0.01 | Aug 12, 2025 | Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. | ||
| CVE-2025-50157 | Med | 0.37 | 5.7 | 0.01 | Aug 12, 2025 | Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. | ||
| CVE-2025-50156 | Med | 0.37 | 5.7 | 0.01 | Aug 12, 2025 | Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network. | ||
| CVE-2025-59510 | Med | 0.36 | 5.5 | 0.01 | Nov 11, 2025 | Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service locally. | ||
| CVE-2026-57096 | Hig | 0.00 | 7.8 | 0.00 | Jul 14, 2026 | Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-50451 | Hig | 0.00 | 7.1 | 0.00 | Jul 14, 2026 | Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. | ||
| CVE-2026-49791 | Hig | 0.00 | 7.1 | 0.00 | Jul 14, 2026 | Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally. |
- risk 0.42cvss 6.5epss 0.02
Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.02
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Buffer over-read in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.02
Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability
- risk 0.37cvss 5.7epss 0.01
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.
- risk 0.37cvss 5.7epss 0.01
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.
- risk 0.37cvss 5.7epss 0.01
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.
- risk 0.37cvss 5.7epss 0.01
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.
- risk 0.37cvss 5.7epss 0.01
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.
- risk 0.37cvss 5.7epss 0.01
Use of uninitialized resource in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to disclose information over a network.
- risk 0.36cvss 5.5epss 0.01
Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to deny service locally.
- risk 0.00cvss 7.8epss 0.00
Heap-based buffer overflow in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.1epss 0.00
Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
- risk 0.00cvss 7.1epss 0.00
Improper link resolution before file access ('link following') in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
Page 6 of 6