cbcvebase.
CVE-2025-21309
published 2025-01-14

CVE-2025-21309: Windows Remote Desktop Services Remote Code Execution Vulnerability

PriorityP261high8.1CVSS 3.1
AVNACHPRNUINSUCHIHAH
EPSS
14.98%
96.3th percentile
Windows Remote Desktop Services Remote Code Execution Vulnerability

Affected

31 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_server_2012
microsoftwindows_server_2012>= 6.2.9200.0 < 6.2.9200.252736.2.9200.25273
microsoftwindows_server_2012_r2>= 6.3.9600.0 < 6.3.9600.223716.3.9600.22371
microsoftwindows_server_2016< 10.0.14393.769910.0.14393.7699
microsoftwindows_server_2016>= 10.0.14393.0 < 10.0.14393.769910.0.14393.7699
microsoftwindows_server_2019< 10.0.17763.677510.0.17763.6775
microsoftwindows_server_2019>= 10.0.17763.0 < 10.0.17763.677510.0.17763.6775
microsoftwindows_server_2022< 10.0.20348.309110.0.20348.3091
microsoftwindows_server_2022>= 10.0.20348.0 < 10.0.20348.309110.0.20348.3091
microsoftwindows_server_2022_23h2< 10.0.25398.136910.0.25398.1369
microsoftwindows_server_2025< 10.0.26100.289410.0.26100.2894
microsoftwindows_server_2025>= 10.0.26100.0 < 10.0.26100.289410.0.26100.2894
msrccbl_mariner_1.0_arm
msrccbl_mariner_1.0_x64
msrccbl_mariner_2.0_arm
msrccbl_mariner_2.0_x64
msrcredis-5.0.5-6.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm
msrcredis-5.0.5-6.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64
msrcredis-6.2.6-1.cm2.aarch64.rpm_on_cbl_mariner_2.0_arm
msrcredis-6.2.6-1.cm2.x86_64.rpm_on_cbl_mariner_2.0_x64
msrcredis-debuginfo-5.0.5-6.cm1.aarch64.rpm_on_cbl_mariner_1.0_arm
msrcredis-debuginfo-5.0.5-6.cm1.x86_64.rpm_on_cbl_mariner_1.0_x64
msrcredis-debuginfo-6.2.6-1.cm2.aarch64.rpm_on_cbl_mariner_2.0_arm
msrcredis-debuginfo-6.2.6-1.cm2.x86_64.rpm_on_cbl_mariner_2.0_x64
msrcwindows_server_2012

Detection & IOCsextracted from sources · hover to see the quote

  • Target systems must have the Remote Desktop Gateway role enabled; monitor for unexpected or repeated RDP Gateway connection attempts which may indicate race condition exploitation attempts
  • Exploitation requires winning a race condition (AC:H); look for high-frequency, rapid repeated connection attempts to the Remote Desktop Gateway service as a behavioral indicator
  • Exploitation likelihood is rated 'More Likely' for latest software releases despite no known active exploitation; prioritize detection and patching on RD Gateway hosts
  • ·Vulnerability is specific to systems running the Windows Remote Desktop Gateway role; systems without this role are not affected attack surface
  • ·Customer action is required; patching is mandatory and not automatic — relevant KBs include KB5050008, KB5049983, KB5050009, KB5049984, KB5049993, KB5050004, KB5050048

CVSS provenance

nvdv3.18.1HIGHCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.