CVE-2025-26671
8.1
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.2 / Impact: 5.9
Source: secure@microsoft.com (Secondary)
Description
Use after free in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
Affected (8)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version r2 sp1 | |
| All versions | |
| Before 10.0.14393.7969 | |
| Before 10.0.17763.7136 | |
| Before 10.0.20348.3453 | |
| Before 10.0.25398.1551 | |
| Before 10.0.26100.3775 |
Related CWEs
CWE-416
Use After Free
The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.
CWE-591
Sensitive Data Storage in Improperly Locked Memory
The product stores sensitive data in memory that is not locked, or that has been incorrectly locked, which might cause the memory to be written to swap files on disk by the virtual memory manager. This can make the data more accessible to external actors.
References (1)
Source: secure@microsoft.com
Vendor Advisory
Timeline
No history available yet.