Executive brief
Remote Desktop Gateway Service is a Microsoft Windows component that manages remote access connections for enterprise environments. A double-free memory corruption vulnerability allows an authorized local user to crash the service or execute arbitrary code with elevated privileges, potentially compromising the integrity and availability of remote access infrastructure.
Technical details
A double-free vulnerability exists in the Remote Desktop Gateway Service due to improper memory management in the affected component. An authenticated local attacker can trigger the double-free condition to corrupt heap memory, leading to denial of service or potential code execution with elevated privileges. The attack requires local system access and valid credentials. Microsoft has released security patches to address this memory safety issue.
Affected products
- Microsoft Windows <UNKNOWN>
Timeline
- 2026-09-08: disclosed