CVE-2025-24045: Windows Remote Desktop Services Remote Code Execution Vulnerability
Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
Other sources
Windows Remote Desktop Services Remote Code Execution Vulnerability
— Microsoft
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What are the potential impacts of CVE-2025-24045 on Windows Remote Desktop Services?
CVE-2025-24045 allows an unauthorized attacker to execute code over a network due to sensitive data being stored in improperly locked memory.
Which versions of Windows Server are affected by CVE-2025-24045?
CVE-2025-24045 affects Windows Server 2012, 2016, 2019, 2022, and 2025, including Server Core installations.
What is the recommended fix for CVE-2025-24045?
Applying the relevant security patches available from Microsoft is the recommended fix for CVE-2025-24045.
How can organizations mitigate the risks associated with CVE-2025-24045?
Organizations can mitigate risks by ensuring that their Windows Server installations are updated with the latest security patches.
Is CVE-2025-24045 considered a high-severity vulnerability?
Yes, CVE-2025-24045 is classified as a high-severity vulnerability due to the potential for code execution by unauthorized attackers.