Microsoft released an out-of-band hotpatch, KB5084597, to fix remote code execution vulnerabilities in the Windows Routing and Remote Access Service (RRAS) management tool affecting certain Windows 11 Enterprise devices. The cumulative hotpatch (covering CVE-2026-25172, CVE-2026-25173, and CVE-2026-26111) applies in-memory fixes to avoid reboots and is automatically delivered to devices enrolled in the Windows Autopatch hotpatch program. #Windows11 #RRAS
Keypoints
- KB5084597 hotpatch addresses RRAS remote code execution vulnerabilities.
- The flaws are tracked as CVE-2026-25172, CVE-2026-25173, and CVE-2026-26111 and were included in the March 2026 Patch Tuesday.
- Hotpatching performs in-memory patching to apply fixes without requiring a reboot for mission-critical devices.
- The update targets Windows 11 25H2, 24H2, and Windows 11 Enterprise LTSC 2024 systems.
- An authenticated domain attacker could exploit the issue by tricking a domain-joined user into connecting to a malicious server via the RRAS snap-in.