Windows RDP Gateway Flaw Lets Attackers Trigger Denial-of-Service Condition

Windows RDP Gateway Flaw Lets Attackers Trigger Denial-of-Service Condition

Microsoft has issued critical security patches aimed at mitigating two vulnerabilities affecting the Windows Remote Desktop Gateway (RD Gateway) service. These vulnerabilities, identified as CVE-2025-26677 and CVE-2025-29831, pose significant risks to enterprise systems, potentially enabling remote attackers to disrupt services and compromise system integrity.

Remote Desktop Gateway Service DoS Vulnerability – CVE-2025-26677

The flaw in the Remote Desktop Gateway Service arises from excessive resource consumption, which can be exploited by unauthenticated remote attackers to overload system resources, leading to a denial-of-service (DoS) condition. This disruption can severely affect remote connectivity within organizations, especially those that rely on RD Gateway for remote operations.

The vulnerability, categorized under the Common Weakness Enumeration (CWE) as CWE-400 (Uncontrolled Resource Consumption), allows attackers to target systems without requiring user interaction.

An expert in cybersecurity emphasized, “This vulnerability is concerning as it can be exploited remotely by attackers with no credentials, potentially causing widespread disruption in environments where Remote Desktop services are integral.”

Microsoft has rated the flaw as “High” in severity, assigning it a CVSS score of 7.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C). This score highlights the potential for significant service disruption, though it does not compromise data confidentiality or integrity.

The affected systems include several versions of Windows Server, such as Server 2016, Server 2019, Server 2022, and the latest Server 2025. Microsoft has rolled out updates (KB5058383, KB5058392, KB5058385, and KB5058411) to patch these vulnerabilities across all affected versions.

Despite the “low likelihood” of active exploitation according to Microsoft’s threat assessment, it is strongly recommended that administrators apply the security patches promptly as part of their regular maintenance routines.

This vulnerability was uncovered by security researchers k0shl and ʌ!ɔ⊥ojv from Kunlun Lab, who coordinated with Microsoft for the responsible disclosure of the flaw.

Risk FactorsDetails
Affected ProductsWindows Server 2016, Windows Server 2019, Windows Server 2022, Windows Server 2025 (Core and Standard)
ImpactDenial of Service (DoS)
Exploit PrerequisitesNo privileges or user interaction needed; network-based attack; low complexity
CVSS 3.1 Score7.5 (High)

Remote Desktop Gateway RCE Flaw – CVE-2025-29831

A separate but related vulnerability, CVE-2025-29831, impacts the same Remote Desktop Gateway service. This flaw allows attackers to execute remote code via a Use After Free issue.

With a CVSS score of 7.5, the vulnerability necessitates user interaction — specifically requiring an administrator to stop or restart the service to trigger the exploit.

Organizations are urged to address both vulnerabilities during their regular maintenance cycle to minimize risk.

Although no active exploitation has been observed, Remote Desktop Gateway services are often targeted by cybercriminals seeking to breach network defenses.

Given that these services are crucial for enabling secure remote access to internal networks, any organization using Windows Server with Remote Desktop Gateway exposed to the internet should prioritize patching this vulnerability.

Risk FactorsDetails
Affected ProductsWindows Server 2008 R2, 2012/R2, 2016 (Core/Standard), 2019 (Core/Standard), 2022 (Core/Standard), 2025 (Core/Standard)
ImpactRemote Code Execution (RCE)
Exploit PrerequisitesNetwork-based attack (AV:N); High complexity (AC:H); Requires user interaction (admin must restart the service)
CVSS 3.1 Score7.5 (High)

According to Microsoft’s Security Update Guide, CVE-2025-26677 is exploited when an attacker causes “resource exhaustion” within the service, suggesting that the attack could be executed with relative ease once identified by malicious actors.

It is crucial for organizations running the affected Windows Server versions to promptly apply the available security patches from Microsoft. Additionally, reviewing network configurations to restrict access to Remote Desktop Gateway services to trusted networks is highly recommended to reduce potential exposure.

More Articles & Posts