Remote Desktop Client Remote Code Execution Vulnerability
CVE-2024-43533

8.8HIGH

Key Information:

Summary

A remote code execution vulnerability has been identified in Microsoft Remote Desktop Client, enabling an attacker to execute arbitrary code on a user's machine. This vulnerability arises when the software does not properly handle specific input, leading to the potential for unauthorized access and exploitation of sensitive data. Users and administrators are advised to apply security updates promptly to mitigate risks associated with this vulnerability.

Affected Version(s)

Remote Desktop client for Windows Desktop Unknown 1.2.0.0 < 1.2.5709.0

Windows 11 version 21H2 x64-based Systems 10.0.0 < 10.0.22000.3260

Windows 11 version 22H2 ARM64-based Systems 10.0.0 < 10.0.22621.4317

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre DatabaseMicrosoft Feed
.