CVE-2025-24045 | Microsoft Windows Server 2012 up to Server 2022 23H2 Remote Desktop Services sensitive data storage in improperly locked memory (Nessus ID 232622)
A vulnerability was found in Microsoft Windows Server 2012 up to Server 2022 23H2. It has been classified as critical. Affected is an unknown function of the component Remote Desktop Services. The manipulation leads to sensitive data storage in improperly locked memory.
This vulnerability is traded as CVE-2025-24045. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to apply a patch to fix this issue.