ZeroHour

CVE-2026-70570

large

Use-after-free RCE in Windows Routing and Remote Access Service (RRAS)

CVSS 3.1
7.5 high
EPSS
<1%p36
Published
()
Modified
AI analysis

CVE-2026-70570 is a use-after-free (CWE-416) memory-corruption flaw in Microsoft's Windows Routing and Remote Access Service (RRAS) that permits unauthenticated remote code execution. An attacker on an adjacent network (e.g., a connected VPN client, LAN segment, or routed peer of an RRAS-enabled host) can trigger the bug by sending crafted traffic that causes the service to access freed memory; the high attack-complexity score indicates reliable exploitation depends on specific timing or state conditions. Successful exploitation yields code execution with high impact on confidentiality, integrity, and availability, giving the attacker unauthorized control of the affected machine without needing credentials or user interaction. Only Windows systems with the RRAS role/feature explicitly enabled are affected — typically servers acting as VPN endpoints or LAN routers — since the service is not enabled by default. As of now there is no known public proof-of-concept, the flaw is not in CISA's KEV, and EPSS estimates only a 0.4% probability of exploitation within 30 days.

What to do: Identify Windows servers with the RRAS/Remote Access role enabled (e.g., query the RemoteAccess/RemoteAccessServer role via Server Manager or PowerShell) and apply Microsoft's update for CVE-2026-70570 on priority once released. Until patched, reduce attack surface by restricting which networks can reach RRAS endpoints (firewall PPTP/SSTP/L2TP ports) and avoid exposing Windows VPN gateways directly to untrusted networks. Because the vector is adjacent-network, also monitor VPN and routed segments for anomalous connections to RRAS hosts.

Affected
Microsoft Windows Routing and Remote Access Service (RRAS)
Estimated exposure
largetens to low hundreds of thousands of Windows systems with RRAS enabled (estimate) — RRAS is an optional Windows Server role used mainly as on-prem VPN/routing gateways and is not enabled by default, so the affected population is a small slice of the very large Windows installed base; public scans of Windows VPN endpoints…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Remote Code Execution in Windows Routing and Remote Access Service (RRAS) allows attacker to gain an unauthorized access to victim's machine

Weakness
CWE-416
Vector
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.