Use-after-free in Windows Server - CVE-2025-32710
Published: June 10, 2025 / Updated: June 20, 2025
Vulnerability identifier: #VU110750
CSH Severity: High
CVSS v4: 9.2 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2025-32710
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability:
Public exploit is available
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error in Windows Remote Desktop Services. A remote attacker can win a race condition and execute arbitrary code on the target system.
Affected software
Windows Server
How to mitigate CVE-2025-32710
Install updates from vendor's website.
Windows Server - addressed in versions 2008 R2 6.1.7601.27729, 2008 6.0.6003.23279, 2008 6.0.6003.23317, 2012 R2 6.3.9600.22577, 2012 6.2.9200.25475, 2016 10.0.14393.8066, 2019 10.0.17763.7314, 2022 23H2 10.0.25398.1611, 2022 23H2 10.0.25398.1665, 2022 10.0.20348.3630, 2022 10.0.20348.3692, 2025 10.0.26100.3981, 2025 10.0.26100.4061