CVE-2025-49688 is a double free vulnerability in the Windows Routing and Remote Access Service (RRAS) that allows an unauthenticated attacker to execute code over a network. This critical flaw affects multiple versions of Windows Server, including 2012, 2016, 2019, 2022, and 2025. With a CVSS score of 8.8 (HIGH), it presents a significant risk due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While not currently in CISA's KEV catalog, its FAUCET Risk Score of 83/100, combined with community discussion and media coverage, indicates notable attention, though no public exploit code or active exploitation has been confirmed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
r2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2012:r2:*:*:*:*:*:*:* | ||
< 10.0.14393.8246CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:* | ||
< 10.0.17763.7558CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:* | ||
< 10.0.20348.3932CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:* | ||
< 10.0.25398.1732CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.