Microsoft Windows Remote Desktop Services Remote Code Execution Vulnerability

Vulnerability

A remote code execution vulnerability has been identified in Windows Remote Desktop Services. This issue arises from sensitive data being stored in improperly locked memory, which allows an unauthorized attacker to execute code over the network. The vulnerability affects multiple versions of Windows Server, including 2012, 2016, 2019, 2022, and 2025, as well as Windows Server 2022 23H2 Edition.

Impact

Exploitation of this vulnerability allows for remote code execution on the affected system.

Remediation

Users can apply the security updates provided by Microsoft for this vulnerability. These security updates can be downloaded via the Microsoft Update Catalog or through the Windows Server Update Services (WSUS).

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
8.1
impact
7.5
exploitability
7.0
remediation
7.7
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.