CVE-2026-71353
largeWindows RRAS Double Free Allows Local Privilege Elevation
CVE-2026-71353 is a double free memory-corruption flaw (CWE-415) in the Windows Routing and Remote Access Service (RRAS), the Windows component used for routing, VPN and remote-access functionality. An authorized attacker who already holds a low-privileged account on the local machine can trigger the bug by causing the service to free the same memory allocation twice; the attack is local, requires no user interaction, and has high attack complexity, so reliable exploitation may be technically difficult. Successful exploitation allows the attacker to elevate privileges on the affected host, with high impact on confidentiality, integrity and availability. Any Windows system on which the RRAS role/service is enabled and running is affected; specific affected Windows version ranges were not specified in the available data. There is no public proof-of-concept, the issue is not in the CISA KEV catalog, and EPSS assigns only a 0.2% chance of exploitation within 30 days, indicating no confirmed in-the-wild exploitation at this time.
What to do: Inventory Windows systems where the RRAS (RemoteAccess) service is enabled and prioritize them for Microsoft's security update for CVE-2026-71353 as soon as it is available. Until patching, restrict local and remote logon rights on RRAS-enabled servers to trusted, low-risk accounts, since exploitation requires an authorized low-privileged local user. Check Microsoft's advisory for the exact affected version ranges and patch guidance.
| Microsoft Windows Routing and Remote Access Service (RRAS) | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
- Weakness
- CWE-415
- Vector
- CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.