A critical vulnerability in Microsoft's Remote Desktop Gateway (RD Gateway) could allow attackers to remotely execute malicious code on affected systems
See also: Asus DriverHub flaws lead to RCE attacks

The vulnerability, identified as CVE-2025-21297 , was disclosed by Microsoft in the January 2025 security updates and has since been actively exploited in attacks . The vulnerability was discovered and reported by VictorV (Tang Tianwen) of Kunlun Lab and is due to a “use-after-free” (UAF) error , which is triggered by concurrent socket connections during the initialization of the Remote Desktop Gateway service.
Specifically, the vulnerability is located in the aaedge.dll, in the CTsgMsgServer::GetCTsgMsgServerInstance, where a global pointer (m_pMsgSvrInstance) is initialized without the necessary thread synchronization.
The race condition allows exploitation of a timing issue where memory allocation and pointer assignment do not occur at the same time, which could lead to arbitrary code execution. Microsoft has rated the vulnerability with a CVSS score of 8.1, indicating a high level of risk. According to the researchers, successfully exploiting the RD Gateway vulnerability requires an attacker to:
- Connect to a system that performs the role of RD Gateway.
- Trigger simultaneous connections to the RD Gateway service (via multiple sockets).
- Exploit the timing problem, in which memory allocation and pointer assignment do not occur synchronously.
- Cause one connection to replace the pointer, while another connection continues to use it.
See also: Critical Erlang/OTP SSH RCE is very easy to exploit
The attack follows a nine-step sequence, with heap collisions between threads, which ultimately lead to the use of already freed memory — which paves the way for arbitrary code execution.

Many versions of Windows Server that use RD Gateway for secure remote access are vulnerable. Organizations that rely on RD Gateway as a primary access point for employees, contractors, or partners working remotely are at particularly high risk.
Microsoft addressed the vulnerability with the May 2025 security update (Patch Tuesday), implementing mutex -based synchronization , thus ensuring that only one thread can initialize the global interface (global instance) at a time.
Security experts strongly recommend that you apply the relevant patches immediately.
"This vulnerability poses a critical risk to enterprise environments that rely on Remote Desktop Gateway for secure remote access," said a security researcher with knowledge of the matter.
See also: MITRE: Funding for critical CVE program ends
The CVE-2025-21297 vulnerability once again highlights the serious risks associated with services , especially when they are used as central entry points into corporate networks. RD Gateway, while designed to provide secure access via RDP, becomes a vulnerable point when critical security updates for the vulnerabilities are not applied in a timely manner.
Source: cybersecuritynews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
