CVE-2023-35365: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.6085Patch KB5028169 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.20048Patch KB5028186 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.3208Patch KB5028166 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.21063Fixed in 6.3.9600.21075Patch KB5028223 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.26623Patch KB5028224 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.24374Patch KB5028233 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.22175Patch KB5028226 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.1992Patch KB5028185 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.3208Patch KB5028166 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.1850Patch KB5028171 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.2176Patch KB5028182 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.4645Patch KB5028168
Event History
Frequently Asked Questions
What is the severity of CVE-2023-35365?
CVE-2023-35365 has been classified as a Remote Code Execution vulnerability.
How do I fix CVE-2023-35365?
To fix CVE-2023-35365, install the latest security updates provided by Microsoft.
Which software is affected by CVE-2023-35365?
CVE-2023-35365 affects various versions of Windows 10, Windows Server 2016, 2019, 2022, and Windows Server 2012 R2.
Is CVE-2023-35365 a local or remote vulnerability?
CVE-2023-35365 is a remote code execution vulnerability, which can be exploited over networks.
What could happen if CVE-2023-35365 is exploited?
If CVE-2023-35365 is exploited, an attacker could execute arbitrary code on the affected system.