PT-2025-20938 · Microsoft · Remote Desktop Gateway Service+1

K0Shl

+1

·

Published

2025-05-13

·

Updated

2026-03-16

·

CVE-2025-26677

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions: Remote Desktop Gateway Service (affected versions not specified)
Description: The issue is related to uncontrolled resource consumption in the Remote Desktop Gateway Service, allowing an unauthorized attacker to deny service over a network. This can halt enterprise remote access.
Recommendations: Apply Microsoft's update KB5050009. As a temporary workaround, consider restricting access to the Remote Desktop Gateway Service to minimize the risk of exploitation.

Fix

DoS

Resource Exhaustion

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

BDU:2025-05672
CVE-2025-26677

Affected Products

Remote Desktop Gateway Service
Windows