Impact
Double free in the Remote Desktop Gateway Service allows an authorized local attacker to elevate privileges. The flaw arises from improper memory management, specifically an earlier free followed by another free on the same resource, which can be exploited to overwrite control data and gain administrative rights on the target system. This results in a complete compromise of confidentiality, integrity, and availability for the affected user account.
Affected Systems
The vulnerability affects Microsoft Windows 10 releases 1607 and 1809, as well as Windows Server 2012 (all editions), Windows Server 2012 R2, Windows Server 2016, Windows Server 2019, Windows Server 2022, and Windows Server 2025, including both full and Server‑Core installations.
Risk and Exploitability
The CVSS score is 7, indicating high severity, but no EPSS data is available and the issue is not listed in the CISA KEV catalog. The attack requires local, authorized access to the system and exploitability relies on the attacker already being present on the machine. If successfully triggered, the attacker can gain privileged local rights and potentially access all system resources.
OpenCVE Enrichment