ZeroHour

CVE-2025-30394

large

Remote Denial-of-Service in Microsoft Windows Server Remote Desktop Gateway Service

CVSS 3.1
5.9 medium
EPSS
30%p98
Published
()
Modified
AI analysis

CVE-2025-30394 is a denial-of-service flaw in the Remote Desktop Gateway (RD Gateway) Service on Windows Server, caused by sensitive data being stored in improperly locked memory (CWE-591) in combination with a race condition (CWE-362). A remote, unauthenticated attacker can trigger it by sending crafted traffic to a network-exposed RD Gateway endpoint (typically TCP 443); the high attack complexity means the attacker must win a timing-sensitive race for the crash to occur. Successful exploitation makes the RD Gateway service fail or stop responding, interrupting remote access for users connecting through the gateway, with no confidentiality or integrity impact. Only servers running the RD Gateway role on Windows Server 2012, 2016, 2019, 2022, 2022 23H2, or 2025 are affected. There is currently no known in-the-wild exploitation, no public proof-of-concept, and the flaw is not in CISA's KEV, but EPSS assigns a 30.5% (98th percentile) probability of exploitation within 30 days.

What to do: Apply Microsoft's security updates for all listed Windows Server versions, prioritizing any RD Gateway server exposed to the internet. Until patched, restrict TCP 443 access to the gateway (firewall allowlists or VPN-only access) and alert on RD Gateway service crashes or unexpected restarts. The high attack complexity makes opportunistic mass exploitation less likely, but the elevated EPSS (~31% within 30 days) justifies prompt patching of internet-facing gateways.

Affected
Microsoft Windows Server (Remote Desktop Gateway Service)Windows Server 2012, Windows Server 2016, Windows Server 2019, Windows Server 2022, Windows Server 2022 23H2, Windows Server 2025 (no specific build ranges prov
Estimated exposure
large≈ tens of thousands of internet-exposed RD Gateway servers (likely on the order of 10k–100k), with an unknown additional population of internal-only deployments — Public internet scans (e.g., Shodan/Censys) have historically identified tens of thousands of hosts presenting RD Gateway/RD Web endpoints on TCP 443, and the RD Gateway role is commonly deployed both internet-facing and internally, so the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Sensitive data storage in improperly locked memory in Remote Desktop Gateway Service allows an unauthorized attacker to deny service over a network.

Vendors
microsoft
Products
windows server 2012, windows server 2016, windows server 2019, windows server 2022, windows server 2022 23h2, windows server 2025
Weakness
CWE-591, CWE-362
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

In the news

No ingested article mentions this CVE yet.