CVE-2026-70570
largeUse-after-free RCE in Windows Routing and Remote Access Service (RRAS)
CVE-2026-70570 is a use-after-free (CWE-416) memory-corruption flaw in Microsoft's Windows Routing and Remote Access Service (RRAS) that permits unauthenticated remote code execution. An attacker on an adjacent network (e.g., a connected VPN client, LAN segment, or routed peer of an RRAS-enabled host) can trigger the bug by sending crafted traffic that causes the service to access freed memory; the high attack-complexity score indicates reliable exploitation depends on specific timing or state conditions. Successful exploitation yields code execution with high impact on confidentiality, integrity, and availability, giving the attacker unauthorized control of the affected machine without needing credentials or user interaction. Only Windows systems with the RRAS role/feature explicitly enabled are affected — typically servers acting as VPN endpoints or LAN routers — since the service is not enabled by default. As of now there is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only a 0.4% probability of exploitation within 30 days.
What to do: Identify Windows servers with the RRAS/Remote Access role enabled (e.g., query the RemoteAccess/RemoteAccessServer role via Server Manager or PowerShell) and apply Microsoft's update for CVE-2026-70570 on priority once released. Until patched, reduce attack surface by restricting which networks can reach RRAS endpoints (firewall PPTP/SSTP/L2TP ports) and avoid exposing Windows VPN gateways directly to untrusted networks. Because the vector is adjacent-network, also monitor VPN and routed segments for anomalous connections to RRAS hosts.
| Microsoft Windows Routing and Remote Access Service (RRAS) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.