CVE-2025-27480: Windows Remote Desktop Services Remote Code Execution Vulnerability
Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.
Other sources
Windows Remote Desktop Services Remote Code Execution Vulnerability
— Microsoft
Affected Software
Event History
Peer vulnerabilities
Found alongside the following vulnerabilities.
Frequently Asked Questions
What is the severity of CVE-2025-27480?
CVE-2025-27480 is classified as a critical vulnerability due to its potential to allow remote code execution.
How do I fix CVE-2025-27480?
To fix CVE-2025-27480, apply the latest security patches provided by Microsoft for the affected Windows Server versions.
What are the affected products for CVE-2025-27480?
CVE-2025-27480 affects multiple versions of Windows Server, including 2022, 2019, 2016, 2012 R2, and 2025.
What can an attacker do with CVE-2025-27480?
An attacker exploiting CVE-2025-27480 can execute arbitrary code on the affected system remotely.
Is CVE-2025-27480 exploited in the wild?
There is currently no confirmation that CVE-2025-27480 is being actively exploited in the wild, but it is recommended to remediate the vulnerability promptly.