Use of uninitialized resource in Windows Server - CVE-2025-50157

 

Use of uninitialized resource in Windows Server - CVE-2025-50157

Published: August 12, 2025


Vulnerability identifier: #VU113871
CSH Severity: Medium
CVSS v4: 6.8 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:A/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-50157
CWE-ID: CWE-908
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to bypass certain security restrictions.

The vulnerability exists due to usage of uninitialized resources in Windows Routing and Remote Access Service (RRAS). A remote user can trigger uninitialized usage of resources and gain access to sensitive information on the system.


Affected software

Windows Server

How to mitigate CVE-2025-50157

Install updates from vendor's website.

Windows Server - addressed in versions 2008 R2 6.1.7601.27872, 2008 6.0.6003.23471, 2012 R2 6.3.9600.22725, 2012 6.2.9200.25622, 2016 10.0.14393.8330, 2019 10.0.17763.7678, 2022 23H2 10.0.25398.1791, 2022 10.0.20348.3989, 2022 10.0.20348.4052, 2025 10.0.26100.4851, 2025 10.0.26100.4946

External References

Related Security Bulletins