CVE-2023-35366: Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Windows Routing and Remote Access Service (RRAS) Remote Code Execution Vulnerability
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.24374Patch KB5028233 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.21063Fixed in 6.3.9600.21075Patch KB5028223 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.26623Patch KB5028224 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.22175Patch KB5028226 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.6085Patch KB5028169 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.3208Patch KB5028166 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.4645Patch KB5028168 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.10240.20048Patch KB5028186 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.3208Patch KB5028166 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22621.1992Patch KB5028185 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22000.2176Patch KB5028182 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.1850Patch KB5028171
Event History
Frequently Asked Questions
What is the severity of CVE-2023-35366?
CVE-2023-35366 has a critical severity level due to its potential for remote code execution.
How do I fix CVE-2023-35366?
To fix CVE-2023-35366, apply the relevant security updates or patches provided by Microsoft for your affected Windows Server or Windows 10 editions.
What are the affected software versions for CVE-2023-35366?
CVE-2023-35366 affects multiple versions of Windows Server 2008 R2, Windows Server 2012 R2, Windows 10, and Windows 11, among others.
Can CVE-2023-35366 be exploited remotely?
Yes, CVE-2023-35366 allows an attacker to execute arbitrary code remotely if the vulnerability is exploited.
What are the potential impacts of CVE-2023-35366?
The impacts of CVE-2023-35366 include unauthorized access to the system and execution of malicious commands.