Impact
A use‑after‑free flaw in the Remote Desktop Gateway Service allows an attacker who already has authorized access to the service over a network to elevate their privileges, potentially gaining higher level rights on the host system.
Affected Systems
Microsoft Windows 10 versions 1607 and 1809, and Microsoft Windows Server releases 2012, 2012 R2, 2016, 2019, 2022, and 2025, including Server Core installations.
Risk and Exploitability
The CVSS score of 7.1 places this vulnerability in the High severity range. The EPSS score of 0.00522 indicates a very low likelihood of exploitation in real‑world scenarios. It is not listed in the CISA KEV catalog. The likely attack vector requires an authorized user to authenticate to the Remote Desktop Gateway Service; from that foothold, the use‑after‑free can be triggered to raise their privileges. The exploit does not appear to rely on arbitrary code execution or network‑wide impact beyond the compromised host.
OpenCVE Enrichment