CVE-2025-21309

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Jan 14, 2025
CWE ID 591

Summary

CVE-2025-21309 is a serious vulnerability affecting Windows Remote Desktop Services. Hackers can exploit this remote code execution flaw to gain unauthorized access to affected systems. By sending specially crafted RDP packets, they can execute arbitrary code on the target machine, potentially installing malware or taking control of it. This issue poses a significant risk to organizations and individuals using Remote Desktop Protocol. Microsoft has released a patch to address the vulnerability, and it is strongly recommended that users install it as soon as possible to protect against potential attacks.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Windows Server 2022

Affected Vendors

  • Microsoft