Remote Desktop Client Remote Code Execution Vulnerability
CVE-2023-29362
8.8HIGH
Key Information:
- Vendor
- Microsoft
- Status
- Vendor
- CVE Published:
- 14 June 2023
Summary
A security flaw has been identified in Microsoft Remote Desktop Client that allows remote code execution. An attacker could exploit this vulnerability to run arbitrary code on a user's system, leading to potential data breaches or unauthorized access. Users are advised to apply the latest updates provided by Microsoft to mitigate these risks.
Affected Version(s)
Remote Desktop client for Windows Desktop Unknown 1.2.0.0 < 1.2.4337.0
Windows 10 Version 1507 x64-based Systems 10.0.10240.0 < 10.0.10240.19983
Windows 10 Version 1607 x64-based Systems 10.0.14393.0 < 10.0.14393.5989
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved