Microsoft Windows Server 2012
cpe:2.3:o:microsoft:windows_server_2012:*:*:*:*:*:*:*
A use-after-free vulnerability has been identified in Windows Remote Desktop Services. This issue allows an unauthorized attacker to execute code remotely over the network. The vulnerability arises from improper handling of memory, leading to a race condition that can be exploited to execute arbitrary code.
Exploitation of this vulnerability could lead to unauthorized remote code execution on the affected system.
To reproduce this vulnerability, connect to a system with the Remote Desktop Gateway role. The exploitation involves triggering a race condition that creates a use-after-free scenario, which can then be leveraged to execute arbitrary code.
Users can apply the security updates released on June 10, 2025, to address this vulnerability. These updates are available through the Microsoft Update Catalog.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.