Remote Code Execution Vulnerability in Microsoft Remote Desktop Connection Client
CVE-2013-1296
Currently unrated
Summary
The Remote Desktop ActiveX control in mstscax.dll suffers from improper memory management within Microsoft Remote Desktop Connection Client 6.1 and 7.0. Exploitation of this vulnerability allows attackers to execute arbitrary code by manipulating memory and accessing deleted objects. Attackers can leverage web pages to trigger this access or gain control through compromised RDP servers, thereby posing significant risks to users who have these clients installed.
References
EPSS Score
51% chance of being exploited in the next 30 days.
Timeline
Vulnerability published
Vulnerability Reserved