Microsoft Windows Server 2012
cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:*
A use-after-free vulnerability has been identified in Windows Remote Desktop Services. This issue allows an unauthorized attacker to execute code remotely over a network. The vulnerability arises from a race condition that creates a use-after-free scenario, which can be exploited to execute arbitrary code on the affected system.
Exploitation of this vulnerability could lead to unauthorized remote code execution on the affected system.
To reproduce this vulnerability, connect to a system with the Remote Desktop Gateway role. The exploitation involves triggering the race condition that creates the use-after-free scenario, which can then be leveraged to execute arbitrary code.
Users can apply the security updates provided by Microsoft to address this vulnerability. These security updates can be downloaded via the Microsoft Update Catalog.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.