A serious vulnerability in Microsoft's Windows Remote Desktop could allow attackers to remotely execute arbitrary code on affected systems without the need for user authentication
See also: Very serious RCE vulnerability discovered in Apache Parquet

This vulnerability, identified as CVE-2025-27480, concerns memory usage after its release in the Remote Desktop Gateway Service and has received a CVSS score of 8.1, indicating high severity and potential impact in enterprise environments worldwide.
Microsoft published an official security bulletin on April 8, 2025, providing details about the vulnerability affecting the Windows Remote Desktop Gateway Service.
The vulnerability, CVE-2025-27480, classified as Use After Free, allows an unauthorized attacker to execute malicious code over a network by exploiting a memory.
The vulnerability has received a CVSS vector critical chain of CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C, indicating that, although the complexity of the attack is high due to the need to win a race condition, no user privileges or interaction are required for exploitation.
See also: Hackers exploit Apache Tomcat RCE vulnerability
The Windows Remote Desktop Gateway service vulnerability occurs when the application incorrectly handles objects in memory, leading to a use-after-free condition. This memory corruption bug creates a scenario where:
- The service allocates memory for an object
- The service releases memory
- The service later refers to the freed memory
- The attacker can manipulate this reference to execute arbitrary code.

The race condition aspect of the vulnerability requires precise timing from potential attackers, which slightly reduces the immediate risk, but does not reduce the overall severity.
Microsoft also announced CVE-2025-27487, a vulnerability rated “Important” that affects the Windows Remote Desktop Client.
This heap-based buffer overflow vulnerability has a CVSS score of 8.0 and could allow attackers controlling a malicious RDP server to execute code on a client machine when a user connects to it.
Unlike CVE-2025-27480, this second vulnerability requires user interaction (UI:R) and low privileges (PR:L), meaning that exploitation will only occur if the user is actively connected to a compromised server.
See also: Veeam RCE flaw allows servers to be compromised
Remote code execution (RCE) refers to the ability to execute arbitrary code or commands on a remote system, typically without the knowledge or permission of the system owner. This can occur when an attacker exploits a vulnerability in a system, application, or network service to gain unauthorized access to it and execute malicious code. RCE is a serious security risk because it can allow attackers to perform actions as if they were the legitimate user, potentially leading to data breaches, system compromise, or further attacks within the network.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
Source: cybersecuritynews
