ZeroHour

CVE-2026-71353

large

Windows RRAS Double Free Allows Local Privilege Elevation

CVSS 3.1
7.0 high
EPSS
<1%p10
Published
()
Modified
AI analysis

CVE-2026-71353 is a double free memory-corruption flaw (CWE-415) in the Windows Routing and Remote Access Service (RRAS), the Windows component used for routing, VPN and remote-access functionality. An authorized attacker who already holds a low-privileged account on the local machine can trigger the bug by causing the service to free the same memory allocation twice; the attack is local, requires no user interaction, and has high attack complexity, so reliable exploitation may be technically difficult. Successful exploitation allows the attacker to elevate privileges on the affected host, with high impact on confidentiality, integrity and availability. Any Windows system on which the RRAS role/service is enabled and running is affected; specific affected Windows version ranges were not specified in the available data. There is no public proof-of-concept, the issue is not in the CISA KEV catalog, and EPSS assigns only a 0.2% chance of exploitation within 30 days, indicating no confirmed in-the-wild exploitation at this time.

What to do: Inventory Windows systems where the RRAS (RemoteAccess) service is enabled and prioritize them for Microsoft's security update for CVE-2026-71353 as soon as it is available. Until patching, restrict local and remote logon rights on RRAS-enabled servers to trusted, low-risk accounts, since exploitation requires an authorized low-privileged local user. Check Microsoft's advisory for the exact affected version ranges and patch guidance.

Affected
Microsoft Windows Routing and Remote Access Service (RRAS)
Estimated exposure
largeon the order of 100,000 Windows systems with RRAS enabled (estimate) — RRAS is a Windows Server role/service that is not enabled by default and is typically deployed on dedicated VPN, NAT or routing servers, so extrapolating from the very large Windows Server install base and public scans showing tens of…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Double free in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

Weakness
CWE-415
Vector
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.