CVE-2025-58737: Remote Desktop Protocol Remote Code Execution Vulnerability
Remote Desktop Protocol Remote Code Execution Vulnerability
Other sources
Use after free in Windows Remote Desktop allows an unauthorized attacker to execute code locally.
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-58737?
CVE-2025-58737 has been classified as a significant remote code execution vulnerability in Windows Remote Desktop.
How do I fix CVE-2025-58737?
To fix CVE-2025-58737, apply the latest security updates provided by Microsoft for your affected Windows Server version.
Which versions of Windows Server are impacted by CVE-2025-58737?
CVE-2025-58737 affects multiple versions of Windows Server, including 2012 R2, 2016, 2019, 2022, 2025, and their respective Server Core installations.
Can CVE-2025-58737 be exploited remotely?
Yes, CVE-2025-58737 can be exploited remotely, allowing attackers to execute code locally on affected systems.
What should I do if I suspect CVE-2025-58737 has been exploited on my server?
If you suspect CVE-2025-58737 has been exploited, immediately isolate the affected server and review logs for unauthorized access or activity.