ThreatCluster

Multiple Vulnerabilities in Windows RRAS Expose Systems to Attacks

First seen 2 Dec 2025, 18:33 UTC Api.Msrc.Microsoft 45

Article Content

Browse articles
ThreatCluster

Microsoft has identified several vulnerabilities in the Windows Routing and Remote Access Service (RRAS), including two remote code execution vulnerabilities (CVE-2025-60715 and CVE-2025-62452), an elevation of privilege vulnerability (CVE-2025-60713), and a denial of service vulnerability (CVE-2025-59510). These vulnerabilities allow authorized attackers to execute code, elevate privileges, or deny service on affected systems. Users of Windows RRAS are advised to apply patches as they become available.