Connect with us

Security

Microsoft Releases Emergency Hotpatch for Windows 11 to Address Critical RRAS RCE Vulnerability

Published

on

Microsoft Releases Hotpatch Update to Fix Windows 11 Security Vulnerabilities

Microsoft has recently issued an out-of-band (OOB) update to address security vulnerabilities impacting Windows 11 Enterprise devices that receive hotpatch updates instead of the regular Patch Tuesday cumulative updates.

The KB5084597 hotpatch update was rolled out to specifically target vulnerabilities in the Windows Routing and Remote Access Service (RRAS) management tool, which could potentially lead to remote code execution when connecting to a malicious server.

According to Microsoft, the security issue affects a limited set of scenarios involving Enterprise client devices running hotpatch updates and being utilized for remote server management.

The KB5084597 update is applicable to Windows 11 versions 25H2 and 24H2, as well as Windows 11 Enterprise LTSC 2024 systems.

Microsoft has identified the vulnerabilities fixed by this hotpatch as CVE-2026-25172, CVE-2026-25173, and CVE-2026-26111, which were initially addressed as part of the March 2026 Patch Tuesday updates.

The company emphasized that the hotpatch update is cumulative, encompassing all fixes and enhancements from the March 2026 Windows security update released on March 10.

While the vulnerabilities were previously resolved on Patch Tuesday, the installation of cumulative updates necessitates device rebooting. However, certain devices used for critical applications and services may not be easily rebooted.

To safeguard such devices, hotpatch updates apply new vulnerability fixes through in-memory patching of running processes, ensuring that the fixes remain in place even after the device reboots.

Microsoft previously released hotfixes for these flaws but re-issued them to ensure comprehensive coverage across all affected scenarios.

See also  Disruption in Communication: Microsoft Exchange Online Outage Halts IMAP4 Access to Mailboxes

Nevertheless, Microsoft specified that the hotpatch will only be provided to devices enrolled in the hotpatch update program and managed through Windows Autopatch, where it will be automatically installed without requiring a restart.

The Red Report 2026: Uncovering New Malware Threats

tines

Malware is evolving, becoming more sophisticated in its tactics. The Red Report 2026 sheds light on how new threats utilize mathematical techniques to detect sandboxes and remain undetected.

Download our comprehensive analysis of 1.1 million malicious samples to discover the top 10 techniques employed by cyber threats and assess the effectiveness of your security measures.

Trending