CVE-2025-24035: Windows Remote Desktop Services Remote Code Execution Vulnerability
Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
Other sources
Windows Remote Desktop Services Remote Code Execution Vulnerability
— Microsoft
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-24035?
CVE-2025-24035 is classified as a critical vulnerability due to the potential for unauthorized code execution.
How do I fix CVE-2025-24035?
To mitigate CVE-2025-24035, apply the latest security patches provided by Microsoft for affected Windows versions.
What software versions are affected by CVE-2025-24035?
CVE-2025-24035 affects various versions of Windows, including Windows 10, Windows 11, and multiple editions of Windows Server.
Is CVE-2025-24035 remotely exploitable?
Yes, CVE-2025-24035 can be exploited remotely if the Windows Remote Desktop Services are exposed to the network.
How can I check if my system is vulnerable to CVE-2025-24035?
You can determine vulnerability to CVE-2025-24035 by verifying whether your Windows installation has the relevant security updates applied.