Double free in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network.
                
            Metrics
Affected Vendors & Products
References
        History
                    Wed, 16 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        
        epss
         
  | 
    
        
        
        epss
         
  | 
Tue, 15 Jul 2025 17:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | 
        
        Microsoft
         Microsoft windows Server 2012 Microsoft windows Server 2016 Microsoft windows Server 2019 Microsoft windows Server 2022 Microsoft windows Server 2022 23h2 Microsoft windows Server 2025  | 
|
| CPEs | cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:* cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:*  | 
|
| Vendors & Products | 
        
        Microsoft
         Microsoft windows Server 2012 Microsoft windows Server 2016 Microsoft windows Server 2019 Microsoft windows Server 2022 Microsoft windows Server 2022 23h2 Microsoft windows Server 2025  | 
Mon, 14 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        
        epss
         
  | 
    
        
        
        epss
         
  | 
Tue, 08 Jul 2025 20:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | 
        
        ssvc
         
  | 
Tue, 08 Jul 2025 17:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | Double free in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to execute code over a network. | |
| Title | Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability | |
| Weaknesses | CWE-415 | |
| References | 
         | |
| Metrics | 
        
        cvssV3_1
         
  | 
Status: PUBLISHED
Assigner: microsoft
Published: 2025-07-08T16:57:14.921Z
Updated: 2025-08-23T00:39:34.959Z
Reserved: 2025-06-09T19:59:44.873Z
Link: CVE-2025-49688
Updated: 2025-07-08T19:21:54.032Z
Status : Analyzed
Published: 2025-07-08T17:15:54.470
Modified: 2025-07-15T17:32:18.167
Link: CVE-2025-49688
No data.