Remote Code Execution Vulnerability in Microsoft Remote Desktop Gateway
CVE-2025-27482
8.1HIGH
Key Information:
- Vendor
- Microsoft
- Status
- Vendor
- CVE Published:
- 8 April 2025
Summary
A vulnerability in the Remote Desktop Gateway Service allows unauthorized attackers to execute code over a network due to sensitive data being stored in improperly locked memory. This could lead to significant security breaches if exploited, making it essential for organizations using this service to implement appropriate security measures.
Affected Version(s)
Windows Server 2016 (Server Core installation) x64-based Systems 10.0.14393.0 < 10.0.14393.7970
Windows Server 2016 x64-based Systems 10.0.14393.0 < 10.0.14393.7970
Windows Server 2019 (Server Core installation) x64-based Systems 10.0.17763.0 < 10.0.17763.7137
References
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved