CVE-2025-32710 is a remote code execution vulnerability in Windows Remote Desktop Services caused by a use-after-free condition. The flaw is reachable over the network by an unauthenticated attacker and arises from a race condition that must be won to trigger use of freed memory. Available reporting indicates the vulnerable exposure is associated with systems configured with the Remote Desktop Gateway role. Successful exploitation could allow arbitrary code execution in the context of the affected service.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a fully automated exploit toolkit targeting Windows systems vulnerable to CVE-2025-32710 (a Remote Desktop Services RCE vulnerability, possibly related to BlueKeep and similar flaws). The main components are: - `run.sh`: A Bash script providing an interactive menu for scanning, attacking, and verifying RDP targets. It orchestrates the workflow, including scanning IP ranges for open RDP ports using Nmap, launching attacks, and verifying successful exploitation. - `sodok.py`: A Python script that acts as a wrapper for the core RDP fingerprinting and exploitation logic. It takes a target IP and port, invokes the `my_rdp.py` library, and outputs results in JSON format. - `my_rdp.py`: The core Python library for RDP protocol interaction, fingerprinting, and NTLM information extraction. It can identify Windows OS versions, check for CredSSP/NTLM support, and is used to inform the attack logic. The exploit works by scanning for RDP endpoints, attempting exploitation (which includes creating a new admin user, enabling RDP, and modifying firewall/registry settings), and verifying access using FreeRDP. Output files (`berhasil.txt`, `scan_lengkap.txt`, `cok.txt`) are used to track targets, scan results, and successful exploits. The toolkit is designed for mass exploitation and verification, with both single-target and bulk/automated modes. The payload is operational and grants persistent access by creating a new administrator account on the target system.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
10 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical remote code execution vulnerability in Windows Remote Desktop.
A remote code execution vulnerability in Windows Remote Desktop Services.
A remote code execution vulnerability in Windows Remote Desktop Services involving a race condition leading to use-after-free.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.