CVE-2025-30394Sensitive Data Storage in Improperly Locked Memory in Microsoft Windows Server 2012

Severity
5.9MEDIUMNVD
EPSS
1.4%
top 19.83%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 13

Description

Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over a network.

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 2.2 | Impact: 3.6

Affected Packages7 packages

NVDmicrosoft/windows< 10.0.14393.8066+5
CVEListV5microsoft/windows_server_20126.2.9200.06.2.9200.25475
CVEListV5microsoft/windows_server_201610.0.14393.010.0.14393.8066
CVEListV5microsoft/windows_server_201910.0.17763.010.0.17763.7314
CVEListV5microsoft/windows_server_202210.0.20348.010.0.20348.3692

🔴Vulnerability Details

2
CVEList
Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability2025-05-13
GHSA
GHSA-787m-4j9v-v659: Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over a network2025-05-13

📋Vendor Advisories

1
Microsoft
Windows Remote Desktop Gateway (RD Gateway) Denial of Service Vulnerability2025-05-13

🕵️Threat Intelligence

1
Bleepingcomputer
Microsoft May 2025 Patch Tuesday fixes 5 exploited zero-days, 72 flaws2025-05-13
CVE-2025-30394 — Microsoft vulnerability | cvebase