Microsoft Remote Desktop client
cpe:2.3:a:microsoft:remote_desktop:*:*:*:*:*:*:*, +4 more
A use-after-free vulnerability has been identified in the Microsoft Remote Desktop Client. This vulnerability allows an unauthorized attacker to execute code on a victim's system over the network. The issue arises when a targeted user connects to a malicious Remote Desktop Protocol (RDP) server, enabling the server to execute code on the user's system within their user context.
Exploitation of this vulnerability could lead to unauthorized remote code execution on the affected system.
Users can download the security update for the Remote Desktop Client for Windows Desktop from the Microsoft Update Catalog. Security updates for various Windows Server versions and Windows 10 and 11 are also available through the Microsoft Update Catalog.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.