Windows App
by Microsoft
CVEs (19)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-59124 | Cri | 0.64 | 9.8 | 0.02 | Aug 11, 2026 | Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-59133 | Hig | 0.57 | 8.8 | 0.01 | Aug 11, 2026 | Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privileges over a network. | ||
| CVE-2026-47289 | Hig | 0.57 | 8.8 | 0.01 | Jun 9, 2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-42985 | Hig | 0.57 | 8.8 | 0.01 | Jun 9, 2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-58718 | Hig | 0.57 | 8.8 | 0.01 | Oct 14, 2025 | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-48817 | Hig | 0.57 | 8.8 | 0.01 | Jul 8, 2025 | Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-29966 | Hig | 0.57 | 8.8 | 0.01 | May 13, 2025 | Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-26645 | Hig | 0.57 | 8.8 | 0.03 | Mar 11, 2025 | Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | ||
| CVE-2024-49105 | Hig | 0.55 | 8.4 | 0.02 | Dec 12, 2024 | Remote Desktop Client Remote Code Execution Vulnerability | ||
| CVE-2025-27487 | Hig | 0.52 | 8.0 | 0.01 | Apr 8, 2025 | Heap-based buffer overflow in Remote Desktop Client allows an authorized attacker to execute code over a network. | ||
| CVE-2021-26860 | Hig | 0.51 | 7.8 | 0.01 | Mar 11, 2021 | Windows App-V Overlay Filter Elevation of Privilege Vulnerability | ||
| CVE-2020-0919 | Hig | 0.51 | 7.8 | 0.01 | Apr 15, 2020 | An elevation of privilege vulnerability exists in Remote Desktop App for Mac in the way it allows an attacker to load unsigned binaries, aka 'Microsoft Remote Desktop App for Mac Elevation of Privilege Vulnerability'. | ||
| CVE-2026-44801 | Hig | 0.49 | 7.5 | 0.00 | Jun 9, 2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-44799 | Hig | 0.49 | 7.5 | 0.00 | Jun 9, 2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-42992 | Hig | 0.49 | 7.5 | 0.00 | Jun 9, 2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-42909 | Hig | 0.49 | 7.5 | 0.00 | Jun 9, 2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | ||
| CVE-2025-32715 | Med | 0.42 | 6.5 | 0.01 | Jun 10, 2025 | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-23656 | Med | 0.38 | 5.9 | 0.00 | Mar 10, 2026 | Insufficient verification of data authenticity in Windows App Installer allows an unauthorized attacker to perform spoofing over a network. | ||
| CVE-2026-21517 | Med | 0.31 | 4.7 | 0.00 | Feb 10, 2026 | Improper link resolution before file access ('link following') in Windows App for Mac allows an authorized attacker to elevate privileges locally. |
- risk 0.64cvss 9.8epss 0.02
Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privileges over a network.
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.01
Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network.
- risk 0.57cvss 8.8epss 0.03
Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- risk 0.55cvss 8.4epss 0.02
Remote Desktop Client Remote Code Execution Vulnerability
- risk 0.52cvss 8.0epss 0.01
Heap-based buffer overflow in Remote Desktop Client allows an authorized attacker to execute code over a network.
- risk 0.51cvss 7.8epss 0.01
Windows App-V Overlay Filter Elevation of Privilege Vulnerability
- risk 0.51cvss 7.8epss 0.01
An elevation of privilege vulnerability exists in Remote Desktop App for Mac in the way it allows an attacker to load unsigned binaries, aka 'Microsoft Remote Desktop App for Mac Elevation of Privilege Vulnerability'.
- risk 0.49cvss 7.5epss 0.00
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- risk 0.49cvss 7.5epss 0.00
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- risk 0.49cvss 7.5epss 0.00
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- risk 0.49cvss 7.5epss 0.00
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- risk 0.42cvss 6.5epss 0.01
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
- risk 0.38cvss 5.9epss 0.00
Insufficient verification of data authenticity in Windows App Installer allows an unauthorized attacker to perform spoofing over a network.
- risk 0.31cvss 4.7epss 0.00
Improper link resolution before file access ('link following') in Windows App for Mac allows an authorized attacker to elevate privileges locally.