CVE-2025-24035Sensitive Data Storage in Improperly Locked Memory in Microsoft Windows 10 Version 1507

Severity
8.1HIGHNVD
EPSS
0.5%
top 34.97%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 11

Description

Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages26 packages

NVDmicrosoft/windows< 10.0.14393.7876+5
NVDmicrosoft/windows_10_1507< 10.0.10240.20947
NVDmicrosoft/windows_10_1607< 10.0.14393.7876
NVDmicrosoft/windows_10_1809< 10.0.17763.7009
NVDmicrosoft/windows_10_21h2< 10.0.19044.5608

🔴Vulnerability Details

2
GHSA
GHSA-7r2v-48c6-xjmm: Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network2025-03-11
CVEList
Windows Remote Desktop Services Remote Code Execution Vulnerability2025-03-11

📋Vendor Advisories

1
Microsoft
Windows Remote Desktop Services Remote Code Execution Vulnerability2025-03-11

🕵️Threat Intelligence

7
Qualys
Microsoft and Adobe Patch Tuesday, March 2025 Security Update Review2025-03-11
Talos
Microsoft Patch Tuesday for March 2025 — Snort rules and prominent vulnerabilities2025-03-11
Tenable
Microsoft’s March 2025 Patch Tuesday Addresses 56 CVEs (CVE-2025-26633, CVE-2025-24983, CVE-2025-24993)2025-03-11
Talos
Microsoft Patch Tuesday for March 2025 — Snort rules and prominent vulnerabilities2025-03-11
Qualys
Microsoft and Adobe Patch Tuesday, March 2025 Security Update Review | Qualys2025-03-11
CVE-2025-24035 — Microsoft vulnerability | cvebase