HomeSecurityRD Gateway UAF vulnerability allows RCE

RD Gateway UAF vulnerability allows RCE

A critical vulnerability in Microsoft's Remote Desktop Gateway (RD Gateway) could allow attackers to remotely execute malicious code on affected systems

See also: Asus DriverHub flaws lead to RCE attacks

RD Gateway Vulnerability

The vulnerability, identified as CVE-2025-21297 , was disclosed by Microsoft in the January 2025 security updates and has since been actively exploited in attacks . The vulnerability was discovered and reported by VictorV (Tang Tianwen) of Kunlun Lab and is due to a “use-after-free” (UAF) error , which is triggered by concurrent socket connections during the initialization of the Remote Desktop Gateway service.

Specifically, the vulnerability is located in the aaedge.dll, in the CTsgMsgServer::GetCTsgMsgServerInstance, where a global pointer (m_pMsgSvrInstance) is initialized without the necessary thread synchronization.

The race condition allows exploitation of a timing issue where memory allocation and pointer assignment do not occur at the same time, which could lead to arbitrary code execution. Microsoft has rated the vulnerability with a CVSS score of 8.1, indicating a high level of risk. According to the researchers, successfully exploiting the RD Gateway vulnerability requires an attacker to:

  • Connect to a system that performs the role of RD Gateway.
  • Trigger simultaneous connections to the RD Gateway service (via multiple sockets).
  • Exploit the timing problem, in which memory allocation and pointer assignment do not occur synchronously.
  • Cause one connection to replace the pointer, while another connection continues to use it.

See also: Critical Erlang/OTP SSH RCE is very easy to exploit

The attack follows a nine-step sequence, with heap collisions between threads, which ultimately lead to the use of already freed memory — which paves the way for arbitrary code execution.

RD Gateway UAF vulnerability allows RCE
RD Gateway UAF vulnerability allows RCE

Many versions of Windows Server that use RD Gateway for secure remote access are vulnerable. Organizations that rely on RD Gateway as a primary access point for employees, contractors, or partners working remotely are at particularly high risk.

Microsoft addressed the vulnerability with the May 2025 security update (Patch Tuesday), implementing mutex -based synchronization , thus ensuring that only one thread can initialize the global interface (global instance) at a time.

Security experts strongly recommend that you apply the relevant patches immediately.
"This vulnerability poses a critical risk to enterprise environments that rely on Remote Desktop Gateway for secure remote access," said a security researcher with knowledge of the matter.

See also: MITRE: Funding for critical CVE program ends

The CVE-2025-21297 vulnerability once again highlights the serious risks associated with services , especially when they are used as central entry points into corporate networks. RD Gateway, while designed to provide secure access via RDP, becomes a vulnerable point when critical security updates for the vulnerabilities are not applied in a timely manner.

Source: cybersecuritynews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS