ThreatCluster

Multiple Vulnerabilities in Windows RRAS Expose Systems to Remote Code Execution and More

First seen 12 Nov 2025, 21:25 UTC Api.Msrc.Microsoft 52

Article Content

Browse articles
ThreatCluster

Microsoft has identified several vulnerabilities in the Windows Routing and Remote Access Service (RRAS), including two heap-based buffer overflow vulnerabilities (CVE-2025-60715 and CVE-2025-62452) that allow authorized attackers to execute code remotely. Additionally, there is an elevation of privilege vulnerability (CVE-2025-60713) and a denial of service vulnerability (CVE-2025-59510) that could be exploited locally. These vulnerabilities affect systems utilizing RRAS, necessitating immediate attention from administrators.