6.5

CVE-2025-49671

Windows Routing and Remote Access Service (RRAS) Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Windows Routing and Remote Access Service (RRAS) allows an unauthorized attacker to disclose information over a network.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Microsoft ≫ Windows Server 2008 Version - Update sp2 HwPlatform x64
Microsoft ≫ Windows Server 2008 Version - Update sp2 HwPlatform x86
Microsoft ≫ Windows Server 2008 Version r2 Update sp1 HwPlatform x64
Microsoft ≫ Windows Server 2016 Version < 10.0.14393.8246
Microsoft ≫ Windows Server 2019 Version < 10.0.17763.7558
Microsoft ≫ Windows Server 2022 Version < 10.0.20348.3932
Microsoft ≫ Windows Server 2022 23h2 Version < 10.0.25398.1732
Microsoft ≫ Windows Server 2025 Version < 10.0.26100.4652
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.99% 0.579
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Microsoft 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

CWE-200 Exposure of Sensitive Information to an Unauthorized Actor

The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-49671
Vendor Advisory