CVE-2026-50451
Analyzed Analyzed - Analysis Complete

Missing Authentication in Windows RRAS Elevates Privileges

Vulnerability report for CVE-2026-50451, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-14

Last updated on: 2026-07-22

Assigner: Microsoft Corporation

Description

Missing authentication for critical function in Windows Routing and Remote Access Service (RRAS) allows an authorized attacker to elevate privileges locally.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-14
Last Modified
2026-07-22
Generated
2026-08-04
AI Q&A
2026-07-15
EPSS Evaluated
2026-08-02
NVD
EUVD

Affected Vendors & Products

Showing 22 associated CPEs
Vendor Product Version / Range
microsoft windows_server_2012 r2
microsoft windows_server_2012 *
microsoft windows_11_26h1 to 10.0.28000.2269 (exc)
microsoft windows_10_1607 to 10.0.14393.9339 (exc)
microsoft windows_10_1607 to 10.0.14393.9339 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_10_1809 to 10.0.17763.9020 (exc)
microsoft windows_server_2016 to 10.0.14393.9339 (exc)
microsoft windows_server_2019 to 10.0.17763.9020 (exc)
microsoft windows_server_2022 to 10.0.20348.5386 (exc)
microsoft windows_server_2025 to 10.0.26100.33158 (exc)
microsoft windows_11_26h1 to 10.0.28000.2525 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_11_24h2 to 10.0.26100.8875 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_21h2 to 10.0.19044.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_10_22h2 to 10.0.19045.7548 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)
microsoft windows_11_25h2 to 10.0.26200.8875 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-50451 is a vulnerability in the Windows Routing and Remote Access Service (RRAS). It involves a missing authentication mechanism for a critical function, which allows an attacker who is already authorized on the system to elevate their privileges locally.

This means the attacker must have some level of access to the system (e.g., a low-privileged user account) but can exploit this flaw to gain higher privileges, such as administrative control.

Detection Guidance

Detection requires checking for unauthorized privilege escalation attempts in Windows Routing and Remote Access Service (RRAS). Monitor RRAS logs for unusual activity and verify authentication mechanisms are enforced. No specific commands are provided in available resources.

Impact Analysis

If you are using a system with the Windows Routing and Remote Access Service (RRAS) enabled, this vulnerability could impact you in the following ways:

  • An attacker with local access to your system could exploit this flaw to gain elevated privileges, such as administrative rights.
  • Once elevated, the attacker could perform unauthorized actions, such as installing malware, accessing sensitive data, or disrupting system operations.
  • This could lead to data breaches, system compromise, or further lateral movement within a network if the affected system is part of a larger infrastructure.
Compliance Impact

This vulnerability could impact compliance with common standards and regulations in the following ways:

  • GDPR: If the affected system processes or stores personal data of EU citizens, a successful exploit could lead to unauthorized access or disclosure of this data. This may violate GDPR requirements for data protection and could result in fines or legal action.
  • HIPAA: For organizations handling protected health information (PHI), this vulnerability could allow unauthorized access to sensitive patient data. This may constitute a breach under HIPAA, leading to penalties and mandatory reporting.
  • Other standards (e.g., ISO 27001, NIST): The vulnerability represents a failure to implement proper access controls and authentication mechanisms, which are core requirements for maintaining security and compliance under these frameworks.

Organizations should assess their exposure and apply patches or mitigations to avoid potential compliance violations.

Mitigation Strategies

Apply the security update provided by Microsoft to address CVE-2026-50451. The update can be found in the Microsoft Update Guide for this vulnerability.

  • Ensure that all systems running Windows Routing and Remote Access Service (RRAS) are updated to the latest patched version.
  • Restrict local access to systems running RRAS to only authorized users to minimize the risk of exploitation.
  • Monitor Microsoft's security advisories for any additional guidance or updates related to this vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-50451. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart