CVE-2025-58737Use After Free in Microsoft Windows Server 2012 R2

CWE-416Use After Free4 documents4 sources
Severity
7.0HIGHNVD
EPSS
0.1%
top 81.53%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 14

Description

Use after free in Windows Remote Desktop allows an unauthorized attacker to execute code locally.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.0 | Impact: 5.9

Affected Packages6 packages

NVDmicrosoft/windows< 10.0.17763.7919+4
CVEListV5microsoft/windows_server_201610.0.14393.010.0.14393.8519
CVEListV5microsoft/windows_server_201910.0.17763.010.0.17763.7919
CVEListV5microsoft/windows_server_202210.0.20348.010.0.20348.4294
CVEListV5microsoft/windows_server_202510.0.26100.010.0.26100.6899

🔴Vulnerability Details

2
GHSA
GHSA-4wrm-6rc2-jx27: Use after free in Windows Remote Desktop allows an unauthorized attacker to execute code locally2025-10-14
CVEList
Remote Desktop Protocol Remote Code Execution Vulnerability2025-10-14

📋Vendor Advisories

1
Microsoft
Remote Desktop Protocol Remote Code Execution Vulnerability2025-10-14
CVE-2025-58737 — Use After Free in Microsoft | cvebase