Remote Code Execution Vulnerability in Microsoft Remote Desktop Gateway
CVE-2025-27482

8.1HIGH

Summary

A vulnerability in the Remote Desktop Gateway Service allows unauthorized attackers to execute code over a network due to sensitive data being stored in improperly locked memory. This could lead to significant security breaches if exploited, making it essential for organizations using this service to implement appropriate security measures.

Affected Version(s)

Windows Server 2016 (Server Core installation) x64-based Systems 10.0.14393.0 < 10.0.14393.7970

Windows Server 2016 x64-based Systems 10.0.14393.0 < 10.0.14393.7970

Windows Server 2019 (Server Core installation) x64-based Systems 10.0.17763.0 < 10.0.17763.7137

References

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.