CVE-2026-20843: Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability
Improper access control in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.
Other sources
Windows Routing and Remote Access Service (RRAS) Elevation of Privilege Vulnerability
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.3.9600.22968Patch KB5073696 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.0.6003.23717Patch KB5073700 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.1.7601.28117Patch KB5073699 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.14393.8783Patch KB5073722 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 6.2.9200.25868Patch KB5073698 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.32230Patch KB5073379 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26100.7623Patch KB5074109 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.25398.2092Patch KB5073450 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.22631.6491Patch KB5073455 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.26200.7623Patch KB5074109 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19045.6809Patch KB5073724 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.19044.6809Patch KB5073724 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.20348.4648Patch KB5073457 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 10.0.17763.8276Patch KB5073723
Event History
Frequently Asked Questions
What is the severity of CVE-2026-20843?
CVE-2026-20843 is classified as a critical elevation of privilege vulnerability in Windows Routing and Remote Access Service.
How do I fix CVE-2026-20843?
To mitigate CVE-2026-20843, you should apply the recommended security updates and patches provided by Microsoft.
What types of systems are affected by CVE-2026-20843?
CVE-2026-20843 affects various versions of Windows Server and Windows operating systems, including Server 2008, 2012, 2016, and Windows 10 and 11.
Can CVE-2026-20843 be exploited remotely?
CVE-2026-20843 requires local access for exploitation, as it allows an attacker to elevate privileges on the affected system.
When was CVE-2026-20843 disclosed?
CVE-2026-20843 was disclosed as a security vulnerability in recent Microsoft updates.