Remote Desktop Client Remote Code Execution Vulnerability
CVE-2024-43533
8.8HIGH
Summary
A remote code execution vulnerability has been identified in Microsoft Remote Desktop Client, enabling an attacker to execute arbitrary code on a user's machine. This vulnerability arises when the software does not properly handle specific input, leading to the potential for unauthorized access and exploitation of sensitive data. Users and administrators are advised to apply security updates promptly to mitigate risks associated with this vulnerability.
Affected Version(s)
Remote Desktop client for Windows Desktop Unknown 1.2.0.0 < 1.2.5709.0
Windows 11 version 21H2 x64-based Systems 10.0.0 < 10.0.22000.3260
Windows 11 version 22H2 ARM64-based Systems 10.0.0 < 10.0.22621.4317
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Collectors
NVD DatabaseMitre DatabaseMicrosoft Feed