Remote Desktop Gateway Service
CVE-2025-27480 — Windows Remote Desktop Services Remote Code Execution Vulnerability
Executive Summary
Use after free in Remote Desktop Gateway Service allows an unauthorized attacker to execute code over a network.
Overview
8.1
CVSS HIGH
Critical
MS Severity
Not Exploited
MS Exploit Status
More Likely
MS Exploit Likelihood
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C
ATTACK VECTOR
Network
ATTACK COMPLEXITY
High
PRIVILEGES REQUIRED
None
USER INTERACTION
None
SCOPE
Unchanged
CONFIDENTIALITY
High
INTEGRITY
High
AVAILABILITY
High
EXPLOIT CODE MATURITY
Unproven
REMEDIATION LEVEL
Official Fix
REPORT CONFIDENCE
Confirmed
Temporal Score: 7.1
EPSS Score
0.09617
probability of exploitation in the next 30 days
0.95041 percentile - updated 2026-08-14
View on FIRST.org
Affected Products
13 affected products
| Product | KB Article | Severity | Impact | Restart Required |
|---|---|---|---|---|
| Windows Server 2012 | 5055581 (Monthly Rollup) |
Critical | Remote Code Execution | Yes |
| Windows Server 2012 (Server Core installation) | 5055581 (Monthly Rollup) |
Critical | Remote Code Execution | Yes |
| Windows Server 2012 R2 | 5055557 (Monthly Rollup) |
Critical | Remote Code Execution | Yes |
| Windows Server 2012 R2 (Server Core installation) | 5055557 (Monthly Rollup) |
Critical | Remote Code Execution | Yes |
| Windows Server 2016 | 5055521 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows Server 2016 (Server Core installation) | 5055521 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows Server 2019 | 5055519 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows Server 2019 (Server Core installation) | 5055519 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows Server 2022 | 5055526 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows Server 2022 (Server Core installation) | 5055526 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows Server 2022, 23H2 Edition (Server Core installation) | 5055527 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows Server 2025 | 5055523 (Security Update) |
Critical | Remote Code Execution | Yes |
| Windows Server 2025 (Server Core installation) | 5055523 (Security Update) |
Critical | Remote Code Execution | Yes |
Patches
7 patches
| Article | Type | Restart |
|---|---|---|
5055581 |
Monthly Rollup | Yes |
5055557 |
Monthly Rollup | Yes |
5055521 |
Security Update | Yes |
5055519 |
Security Update | Yes |
5055526 |
Security Update | Yes |
5055527 |
Security Update | Yes |
5055523 |
Security Update | Yes |
Exploits & PoC
2 public PoCsUnverified third-party code
Public proof-of-concept repositories aggregated from PoC-in-GitHub. They are not reviewed and may be incomplete, non-functional, or malicious — inspect the code before running anything.
| Repository | Stars | Published | Description |
|---|---|---|---|
| mrk336/CVE-2025-27480-The-Silent-Gateway-Risk | 0 | 2025-09-01 | Letting attackers run malicious code without needing a cracked password, user interaction, or even a foothold in your network. That’s CVE-2025-27480 |
| mrk336/CVE-2025-27480 | 0 | 2025-09-03 | CVE-2025-27480 exposes a buffer overflow in OpenSSH 8.9p1 via a malformed SSH_USERAUTH packet. Attackers can inject shellcode and gain SYSTEM-level access, compromising bastion hosts and downstream CI |
Detection Rules
No public Sigma or Nuclei detection rule has been mapped to this CVE yet. Coverage is concentrated on exploited / high-profile vulnerabilities; check SigmaHQ for updates.
Acknowledgments
ʌ!ɔ⊥ojv with Kunlun Lab
References
On This Page