PT-2025-15539 · Microsoft · Remote Desktop Gateway Service+1
Ʌ!Ɔ⊥Ojv
·
Published
2025-04-08
·
Updated
2025-04-13
·
CVE-2025-27480
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Windows Remote Desktop Services (affected versions not specified)
Description:
The issue allows remote attackers to execute arbitrary code and affect the system. This is due to a use-after-free condition in the Windows Remote Desktop Gateway Service, where the application improperly manages memory. An attacker can exploit this flaw by timing their actions accurately to manipulate freed memory references and execute malicious code, significantly impacting device security and integrity. No user interaction or privileges are required for exploitation, increasing the risk for organizations.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Remote Desktop Gateway Service
Windows