CVE-2025-24045Sensitive Data Storage in Improperly Locked Memory in Microsoft Windows Server 2012

Severity
8.1HIGHNVD
EPSS
0.4%
top 38.96%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 11

Description

Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 2.2 | Impact: 5.9

Affected Packages7 packages

NVDmicrosoft/windows< 10.0.14393.7876+5
CVEListV5microsoft/windows_server_20126.2.9200.06.2.9200.25368
CVEListV5microsoft/windows_server_201610.0.14393.010.0.14393.7876
CVEListV5microsoft/windows_server_201910.0.17763.010.0.17763.7009
CVEListV5microsoft/windows_server_202210.0.20348.010.0.20348.3328

🔴Vulnerability Details

2
CVEList
Windows Remote Desktop Services Remote Code Execution Vulnerability2025-03-11
GHSA
GHSA-pgq6-cmg5-ghf7: Sensitive data storage in improperly locked memory in Windows Remote Desktop Services allows an unauthorized attacker to execute code over a network2025-03-11

📋Vendor Advisories

1
Microsoft
Windows Remote Desktop Services Remote Code Execution Vulnerability2025-03-11

🕵️Threat Intelligence

7
Qualys
Microsoft and Adobe Patch Tuesday, March 2025 Security Update Review2025-03-11
Talos
Microsoft Patch Tuesday for March 2025 — Snort rules and prominent vulnerabilities2025-03-11
Tenable
Microsoft’s March 2025 Patch Tuesday Addresses 56 CVEs (CVE-2025-26633, CVE-2025-24983, CVE-2025-24993)2025-03-11
Talos
Microsoft Patch Tuesday for March 2025 — Snort rules and prominent vulnerabilities2025-03-11
Qualys
Microsoft and Adobe Patch Tuesday, March 2025 Security Update Review | Qualys2025-03-11
CVE-2025-24045 — Microsoft vulnerability | cvebase