You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve-2025-49663
About this tag
CVE-2025-49663 is a critical heap-based buffer overflow vulnerability in the Windows Routing and Remote Access Service (RRAS). It allows remote attackers to execute arbitrary code on unpatched RRAS hosts, potentially leading to full system compromise. Administrators should treat any RRAS-enabled servers exposed to untrusted networks as high-priority for patching, isolation, and forensic review. The vulnerability is part of a family of RRAS defects that also includes use-of-uninitialized-resource issues. Confusion over exact CVE identifiers in some advisories underscores the need to verify vendor advisories and KB numbers for each affected OS build before applying patches.
A newly disclosed vulnerability affecting Windows' Routing and Remote Access Service (RRAS) can allow remote attackers to execute code against unpatched RRAS hosts — administrators must treat any RRAS-enabled servers exposed to untrusted networks as high-priority for patching, isolation, and...
A critical vulnerability, identified as CVE-2025-49663, has been discovered in the Windows Routing and Remote Access Service (RRAS), posing a significant risk to systems running this service. This flaw is a heap-based buffer overflow that allows unauthorized attackers to execute arbitrary code...