CNNVD-202508-1215 Information

CNNVD ID

CNNVD-202508-1215

CVE-2025-53153

  • CNNVD Published: 2025-08-12

Description (Chinese)

Microsoft Windows Routing and Remote Access Service是美国微软(Microsoft)公司的一种网络服务,用于实现网络路由、虚拟专用网络(VPN)和拨号连接等功能。 Microsoft Windows Routing and Remote Access Service (RRAS)存在安全漏洞。攻击者利用该漏洞可以获取敏感信息。以下产品和版本受到影响:Windows Server 2022 (Server Core installation),Windows Server 2025 (Server Core installation),Windows Server 2022, 23H2 Edition (Server Core installation),Windows Server 2025,Windows Server 2016,Windows Server 2016 (Server Core installation),Windows Server 2008 for 32-bit Systems Service Pack 2,Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation),Windows Server 2008 for x64-based Systems Service Pack 2,Windows Server 2008 for x64-based Systems Service Pack 2 (Server Core installation),Windows Server 2008 R2 for x64-based Systems Service Pack 1,Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation),Windows Server 2012,Windows Server 2012 (Server Core installation),Windows Server 2012 R2,Windows Server 2012 R2 (Server Core installation),Windows Server 2019,Windows Server 2019 (Server Core installation),Windows Server 2022。

Description (English)

Microsoft Windows Routing and Remote Access Service is a network service of Microsoft Corporation in the United States, which is used to perform network routing, virtual private network (VPN) and dial-up connectivity. Microsoft Windows Routing and Remote Access Service (RRAS) has a security gap. The attackers use that loophole to obtain sensitive information. The following products and versions have been affected: Windows Server 2022 (Server Corporation), Windows Server 2025 (Server Corporation), Windows Server 2022, 23H2 Management (Server Corporation 2025), Windows Service Service 2025, Windows Service Service 2016, Windows Server 2016 (Server Corporation), Windows Server 2008 for 32-bit Systems 2012 Pack System Service, Windows Server 2008 for Service Service Service 2012 Building, Windows Server 2008 for Service Service 2012 Pack2-Setter 2008 Building Building Building Building Building Building Services, and Service Services 2008-Setters 2008-Setter 2008

Hazard Level

High

Vulnerability Type

其他

Affected Vendor

微软

Published

2025-08-12

Last Modified

2026-02-24

References

https://nvd.nist.gov/vuln/detail/CVE-2025-53153 https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53153

Patch

https://msrc.microsoft.com/update-guide/vulnerability/CVE-2025-53153

Share on: