CyberzSOC

Publication detail
← Back to advisories & guidance

2025-009: Critical Vulnerabilities in Windows Remote Desktop Services ↗ source

March 14, 2025 CERT-EU Advisory

Summary

Among the critical vulnerabilities are CVE-2025-24035 and CVE-2025-24045, both Remote Code Execution (RCE) vulnerabilities in Windows Remote Desktop Services (RDS). Each vulnerability has been assigned a CVSSv3 score of 8.1 and is rated as critical [1]. It is recommended updating affected assets as soon as possible. The vulnerability CVE-2025-24035 is caused by sensitive data storage in improperly locked memory and CVE-2025-24045 is a more complex vulnerability to exploit, requiring an attacker Successful exploitation of these vulnerabilities could allow an unauthorised attacker to execute Microsoft has addressed 57 vulnerabilities in its products as part of the March 2025 Patch The following products are affected by CVE-2025-24035 [3]: The following products are affected by CVE-2025-24045 [4]: CERT-EU recommends updating the affected products as soon as possible to the latest version, prioritising Internet facing applications.

News Coverage

No coverage found in monitored research blogs or news feeds.

CVEs Referenced in This Publication

CVECVSSAffected
CVE-2025-24035 8.1 High Microsoft Windows 10 Version 1809 Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.
CVE-2025-24045 8.1 High Microsoft Windows Server 2012 Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

Extracted from the publication text. Each CVE links to its tracked detail page.

Vendors Named in This Publication

Each vendor links to its Known Exploited Vulnerabilities catalog page. Only vendors that appear in the KEV catalog are listed, either because the publication cites one of their KEV entries or because it names them directly.