PT-2025-15539 · Microsoft · Remote Desktop Gateway Service+1

Ʌ!Ɔ⊥Ojv

·

Published

2025-04-08

·

Updated

2025-04-13

·

CVE-2025-27480

CVSS v3.1

8.1

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Windows Remote Desktop Services (affected versions not specified)
Description: The issue allows remote attackers to execute arbitrary code and affect the system. This is due to a use-after-free condition in the Windows Remote Desktop Gateway Service, where the application improperly manages memory. An attacker can exploit this flaw by timing their actions accurately to manipulate freed memory references and execute malicious code, significantly impacting device security and integrity. No user interaction or privileges are required for exploitation, increasing the risk for organizations.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2025-04049
CVE-2025-27480

Affected Products

Remote Desktop Gateway Service
Windows