CVE-2025-27480
Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.
- Affected products
- Remote Desktop Gateway Service, Windows
- Microsoft Windows Server 2012
- All versions
- Microsoft Windows Server 2016
- < 10.0.14393.7969
- Microsoft Windows Server 2019
- < 10.0.17763.7136
- Microsoft Windows Server 2022
- < 10.0.20348.3453
- Microsoft Windows Server 2022 23h2
- < 10.0.25398.1551
- Microsoft Windows Server 2025
- < 10.0.26100.3775
- CVSS 3.1
- 8.1 HIGH
- EPSS
- 9.6% (95th percentile)
- Weakness
- CWE-416
- NVD status
- Analyzed
- Published
- 2025-04-08
CVE-2025-27480 at NVD
2 known exploits for CVE-2025-27480
Proof-of-concept code and exploit modules indexed by Sploitus