cbcvebase.
CVE-2025-58737
published 2025-10-14

CVE-2025-58737: Use after free in Windows Remote Desktop allows an unauthorized attacker to execute code locally.

high7CVSS 3.1
AVLACHPRNUIRSUCHIHAH
Use after free in Windows Remote Desktop allows an unauthorized attacker to execute code locally.

Affected

17 ranges
VendorProductVersion rangeFixed in
microsoftwindows_server_2012
microsoftwindows_server_2012_r2>= 6.3.9600.0 < 6.3.9600.228246.3.9600.22824
microsoftwindows_server_2016<= 10.0.14393.8519
microsoftwindows_server_2016>= 10.0.14393.0 < 10.0.14393.851910.0.14393.8519
microsoftwindows_server_2019< 10.0.17763.791910.0.17763.7919
microsoftwindows_server_2019>= 10.0.17763.0 < 10.0.17763.791910.0.17763.7919
microsoftwindows_server_2022< 10.0.20348.429410.0.20348.4294
microsoftwindows_server_2022>= 10.0.20348.0 < 10.0.20348.429410.0.20348.4294
microsoftwindows_server_2022_23h2< 10.0.25398.191310.0.25398.1913
microsoftwindows_server_2025<= 10.0.26100.6899
microsoftwindows_server_2025>= 10.0.26100.0 < 10.0.26100.689910.0.26100.6899
msrcwindows_server_2012_r2
msrcwindows_server_2016
msrcwindows_server_2019
msrcwindows_server_2022
msrcwindows_server_2022_23h2_edition
msrcwindows_server_2025