Remote Desktop Client Remote Code Execution Vulnerability
CVE-2024-21307
Summary
A vulnerability exists in Microsoft Remote Desktop Client that could allow an authenticated attacker to execute arbitrary code on a remote system. This issue arises from improper validation of user-provided data. Exploitation of this vulnerability requires the attacker to send a specially crafted request, which could lead to unauthorized access or control over the affected system. Users and administrators are advised to apply appropriate security measures and updates from Microsoft to mitigate the risks associated with this vulnerability.
Affected Version(s)
Remote Desktop client for Windows Desktop Unknown 1.2.0.0 < 1.2.5105.0
Windows 10 Version 1507 32-bit Systems 10.0.10240.0 < 10.0.10240.20402
Windows 10 Version 1607 32-bit Systems 10.0.14393.0 < 10.0.14393.6614
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved