Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2025-29959

CVE-2025-29959: Windows 10 1507 Information Disclosure Flaw

CVE-2025-29959 is an information disclosure vulnerability in Windows 10 1507 Routing and Remote Access Service (RRAS) caused by uninitialized resources. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2025-29959 Overview

CVE-2025-29959 is an information disclosure vulnerability in the Windows Routing and Remote Access Service (RRAS). The flaw stems from use of an uninitialized resource [CWE-908], which permits an unauthorized attacker to read memory contents over the network. Exploitation requires user interaction, such as convincing a user to connect to an attacker-controlled server or open a crafted resource.

Microsoft published the advisory on May 13, 2025. The vulnerability affects a broad range of supported Windows client and server editions, including Windows Server 2008 through Windows Server 2025 and Windows 10 and 11 across multiple feature updates.

Critical Impact

Successful exploitation exposes sensitive process memory from RRAS, which may include credentials, session data, or other information useful for follow-on attacks against Windows infrastructure.

Affected Products

  • Microsoft Windows 10 (versions 1507, 1607, 1809, 21H2, 22H2)
  • Microsoft Windows 11 (versions 22H2, 23H2, 24H2)
  • Microsoft Windows Server 2008, 2012, 2016, 2019, 2022, 2022 23H2, and 2025

Discovery Timeline

  • 2025-05-13 - CVE-2025-29959 published to NVD with Microsoft advisory
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2025-29959

Vulnerability Analysis

The vulnerability resides in the Windows Routing and Remote Access Service, a component that provides routing, VPN, and dial-up remote access capabilities for Windows Server and workstation deployments. RRAS processes network protocol packets and maintains internal data structures for routing state, tunnels, and session management.

An attacker who successfully exploits this flaw reads uninitialized memory from RRAS process space over the network. The disclosed data can contain fragments of prior allocations, including protocol buffers, pointers, or credential material. Attackers typically chain information disclosure primitives with other vulnerabilities to bypass mitigations such as Address Space Layout Randomization (ASLR).

The attack does not require authentication, but it does require user interaction. This constraint reduces mass-exploitation risk while still allowing targeted operations against administrators or users interacting with malicious RRAS endpoints.

Root Cause

The root cause is classified as Use of Uninitialized Resource [CWE-908]. RRAS allocates a memory buffer or object without initializing every field before returning contents to a network peer. When the service serializes the structure into a response, stale bytes from previously freed allocations leak to the caller.

Attack Vector

Exploitation occurs over the network against a system running RRAS. The attacker crafts a protocol exchange that triggers the vulnerable code path in RRAS and induces a user to complete the interaction required for the disclosure. The response returned by the service or received by the client contains uninitialized memory contents.

No verified proof-of-concept code is publicly available. Refer to the Microsoft CVE-2025-29959 Advisory for vendor guidance.

Detection Methods for CVE-2025-29959

Indicators of Compromise

  • Unexpected inbound or outbound RRAS traffic on hosts that do not require remote access services
  • Anomalous protocol sequences directed at RRAS listening ports, including malformed or repeated negotiation attempts
  • Windows Event Log entries indicating RRAS service errors, restarts, or unusual client connections

Detection Strategies

  • Monitor RRAS-related event IDs in the System and Application logs for abnormal patterns
  • Deploy network intrusion detection signatures for malformed RRAS and PPTP/L2TP protocol traffic
  • Correlate outbound connections from user endpoints to untrusted RRAS servers with subsequent lateral movement indicators

Monitoring Recommendations

  • Inventory all systems where the RRAS role or service is installed and enabled
  • Baseline normal RRAS client counts and traffic volumes to identify deviations
  • Alert on new RRAS service installations or configuration changes on servers and workstations

How to Mitigate CVE-2025-29959

Immediate Actions Required

  • Apply the May 2025 Microsoft security updates that address CVE-2025-29959 across all affected Windows client and server editions
  • Disable the Routing and Remote Access Service on hosts where it is not required for business operations
  • Restrict RRAS network exposure using host firewalls and perimeter access control lists

Patch Information

Microsoft released patches for all supported Windows versions through the May 2025 Patch Tuesday cycle. Consult the Microsoft CVE-2025-29959 Advisory for the specific KB article and build number matching each affected product.

Workarounds

  • Stop and disable the RemoteAccess service on systems that do not use RRAS functionality
  • Block inbound access to RRAS protocols at the network perimeter and segment RRAS servers into restricted VLANs
  • Train users to avoid connecting to untrusted VPN or remote access endpoints that could trigger the vulnerable code path
bash
# Disable RRAS on systems that do not require it
sc.exe stop RemoteAccess
sc.exe config RemoteAccess start= disabled

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.