ZeroHour

CVE-2026-71351

mass

Double Free in Windows Routing and Remote Access Service (RRAS) Enables Local Privilege Escalation

CVSS 3.1
7.0 high
EPSS
<1%p17
Published
()
Modified
AI analysis

CVE-2026-71351 is a double-free memory corruption flaw (CWE-415) in the Windows Routing and Remote Access Service (RRAS), assigned by Microsoft. To trigger it, an authorized, low-privileged local user must send input that causes the service to free the same memory resource twice; the CVSS vector rates the attack as local (AV:L) with high complexity (AC:H), meaning reliable exploitation requires favorable conditions. A successful attacker gains elevated privileges on the local machine, with high impact on confidentiality, integrity, and availability of the system. Any Windows deployment with the RRAS role or feature enabled is potentially affected, since the flaw resides in the service itself rather than a specific application. There is currently no known exploitation, no public proof-of-concept, it is not in the CISA KEV catalog, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days.

What to do: Apply Microsoft's security update for this CVE via Windows Update on all servers where the Routing and Remote Access Service role is installed. As interim mitigation, disable the RRAS role where it is not actively used and restrict local logon rights on servers that must run it. Inventory Windows systems for the RRAS service being enabled and prioritize patching any that function as VPN or routing gateways.

Affected
Microsoft Windows Routing and Remote Access Service (RRAS)
Estimated exposure
masshundreds of thousands of Windows Server hosts with RRAS enabled (Windows' installed base is in the hundreds of millions; RRAS is a standard role commonly… — RRAS ships with Windows Server as an optional role used for VPN, NAT, and routing, so the potentially affected base is the large Windows Server installed base subsetted to servers running that role, which plausibly exceeds 100,000 exposed…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

Weakness
CWE-415
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.