CVE-2026-71351
massDouble Free in Windows Routing and Remote Access Service (RRAS) Enables Local Privilege Escalation
CVE-2026-71351 is a double-free memory corruption flaw (CWE-415) in the Windows Routing and Remote Access Service (RRAS), assigned by Microsoft. To trigger it, an authorized, low-privileged local user must send input that causes the service to free the same memory resource twice; the CVSS vector rates the attack as local (AV:L) with high complexity (AC:H), meaning reliable exploitation requires favorable conditions. A successful attacker gains elevated privileges on the local machine, with high impact on confidentiality, integrity, and availability of the system. Any Windows deployment with the RRAS role or feature enabled is potentially affected, since the flaw resides in the service itself rather than a specific application. There is currently no known exploitation, no public proof-of-concept, it is not in the CISA KEV catalog, and EPSS estimates only a 0.3% probability of exploitation in the next 30 days.
What to do: Apply Microsoft's security update for this CVE via Windows Update on all servers where the Routing and Remote Access Service role is installed. As interim mitigation, disable the RRAS role where it is not actively used and restrict local logon rights on servers that must run it. Inventory Windows systems for the RRAS service being enabled and prioritize patching any that function as VPN or routing gateways.
| Microsoft Windows Routing and Remote Access Service (RRAS) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-415
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.