Use-after-free in Windows Server - CVE-2025-32710

 

Use-after-free in Windows Server - CVE-2025-32710

Published: June 10, 2025 / Updated: June 20, 2025


Vulnerability identifier: #VU110750
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-32710
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: Public exploit is available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error in Windows Remote Desktop Services. A remote attacker can win a race condition and execute arbitrary code on the target system.


Affected software

Windows Server

How to mitigate CVE-2025-32710

Install updates from vendor's website.

Windows Server - addressed in versions 2008 R2 6.1.7601.27729, 2008 6.0.6003.23279, 2008 6.0.6003.23317, 2012 R2 6.3.9600.22577, 2012 6.2.9200.25475, 2016 10.0.14393.8066, 2019 10.0.17763.7314, 2022 23H2 10.0.25398.1611, 2022 23H2 10.0.25398.1665, 2022 10.0.20348.3630, 2022 10.0.20348.3692, 2025 10.0.26100.3981, 2025 10.0.26100.4061

Links to Public Exploits and PoC-codes

External References

Related Security Bulletins