CVE-2025-27482 is a critical vulnerability affecting Microsoft Windows Server versions 2016 through 2025, where sensitive data is improperly stored in unlocked memory within the Remote Desktop Gateway Service. This allows an unauthenticated attacker to achieve remote code execution over a network with high impact on confidentiality, integrity, and availability, as indicated by its CVSS score of 8.1 (HIGH). While there is no public exploit code or KEV listing, the vulnerability has garnered significant community discussion and media coverage, suggesting high awareness despite no confirmed active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 10.0.14393.7969CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2016:*:*:*:*:*:*:*:* | ||
< 10.0.17763.7136CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2019:*:*:*:*:*:*:*:* | ||
< 10.0.20348.3453CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2022:*:*:*:*:*:*:*:* | ||
< 10.0.25398.1551CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2022_23h2:*:*:*:*:*:*:*:* | ||
< 10.0.26100.3775CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2025:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.