ThreatCluster

Multiple Vulnerabilities in Windows RRAS Allow Remote Code Execution and Information Disclosure

First seen 9 Dec 2025, 18:45 UTC Api.Msrc.Microsoft 58

Article Content

Browse articles
ThreatCluster

Three vulnerabilities have been identified in the Windows Routing and Remote Access Service (RRAS). CVE-2025-62549 and CVE-2025-64678 allow unauthorized remote code execution, while CVE-2025-62473 enables information disclosure. These vulnerabilities affect systems utilizing RRAS, potentially exposing them to attacks over a network.