CVE-2025-24045

CVSS 3.1 Score 8.1 of 10 (high)

Details

Published Mar 11, 2025
CWE ID 591

Summary

CVE-2025-24045 is a newly disclosed vulnerability affecting Windows Remote Desktop Services. The issue permits unauthorized attackers to gain access to sensitive data stored in memory that is not adequately secured. The memory in question is not properly locked, enabling attackers to execute malicious code over a network connection. This vulnerability poses a significant risk, as it can lead to unauthorized system access and potential data theft. Microsoft has released a patch to address this issue, and users are strongly encouraged to install it as soon as possible to mitigate the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Microsoft Windows Server 2022

Affected Vendors

  • Microsoft