Remote Desktop Client
by Microsoft
CVEs (64)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-42992 | Hig | 0.49 | 7.5 | 0.00 | Jun 9, 2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-42913 | Hig | 0.49 | 7.5 | 0.00 | Jun 9, 2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | ||
| CVE-2026-42909 | Hig | 0.49 | 7.5 | 0.00 | Jun 9, 2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | ||
| CVE-2024-21307 | Hig | 0.49 | 7.5 | 0.02 | Jan 9, 2024 | Remote Desktop Client Remote Code Execution Vulnerability | ||
| CVE-2021-43233 | Hig | 0.49 | 7.5 | 0.02 | Dec 15, 2021 | Remote Desktop Client Remote Code Execution Vulnerability | ||
| CVE-2021-38665 | Hig | 0.49 | 7.4 | 0.07 | Nov 10, 2021 | Remote Desktop Protocol Client Information Disclosure Vulnerability | ||
| CVE-2011-0029 | Hig | 0.49 | 7.4 | 0.07 | Mar 9, 2011 | Untrusted search path vulnerability in the client in Microsoft Remote Desktop Connection 5.2, 6.0, 6.1, and 7.0 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .rdp file, aka "Remote… | ||
| CVE-2026-69358 | Hig | 0.46 | 7.1 | 0.01 | Sep 8, 2026 | Use of uninitialized resource in Remote Desktop Client allows an authorized attacker to execute code over a network. | ||
| CVE-2026-77896 | Med | 0.42 | 6.5 | 0.01 | Sep 8, 2026 | Integer overflow or wraparound in Remote Desktop Client allows an unauthorized attacker to deny service over a network. | ||
| CVE-2026-69550 | Med | 0.42 | 6.5 | 0.01 | Aug 19, 2026 | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-61924 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-61921 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2026-61918 | Med | 0.42 | 6.5 | 0.01 | Aug 11, 2026 | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2025-32715 | Med | 0.42 | 6.5 | 0.01 | Jun 10, 2025 | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | ||
| CVE-2023-29352 | Med | 0.42 | 6.5 | 0.01 | Jun 14, 2023 | Windows Remote Desktop Security Feature Bypass Vulnerability | ||
| CVE-2023-28267 | Med | 0.42 | 6.5 | 0.02 | Apr 11, 2023 | Remote Desktop Protocol Client Information Disclosure Vulnerability | ||
| CVE-2022-26940 | Med | 0.42 | 6.5 | 0.03 | May 10, 2022 | Remote Desktop Protocol Client Information Disclosure Vulnerability | ||
| CVE-2022-22015 | Med | 0.42 | 6.5 | 0.03 | May 10, 2022 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability | ||
| CVE-2026-69317 | Med | 0.37 | 5.7 | 0.01 | Sep 8, 2026 | Out-of-bounds read in Remote Desktop Client allows an authorized attacker to disclose information over a network. | ||
| CVE-2022-24503 | Med | 0.35 | 5.4 | 0.02 | Mar 9, 2022 | Remote Desktop Protocol Client Information Disclosure Vulnerability |
- risk 0.49cvss 7.5epss 0.00
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- risk 0.49cvss 7.5epss 0.00
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- risk 0.49cvss 7.5epss 0.00
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
- risk 0.49cvss 7.5epss 0.02
Remote Desktop Client Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.02
Remote Desktop Client Remote Code Execution Vulnerability
- risk 0.49cvss 7.4epss 0.07
Remote Desktop Protocol Client Information Disclosure Vulnerability
- risk 0.49cvss 7.4epss 0.07
Untrusted search path vulnerability in the client in Microsoft Remote Desktop Connection 5.2, 6.0, 6.1, and 7.0 allows local users to gain privileges via a Trojan horse DLL in the current working directory, as demonstrated by a directory that contains a .rdp file, aka "Remote…
- risk 0.46cvss 7.1epss 0.01
Use of uninitialized resource in Remote Desktop Client allows an authorized attacker to execute code over a network.
- risk 0.42cvss 6.5epss 0.01
Integer overflow or wraparound in Remote Desktop Client allows an unauthorized attacker to deny service over a network.
- risk 0.42cvss 6.5epss 0.01
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
- risk 0.42cvss 6.5epss 0.01
Windows Remote Desktop Security Feature Bypass Vulnerability
- risk 0.42cvss 6.5epss 0.02
Remote Desktop Protocol Client Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.03
Remote Desktop Protocol Client Information Disclosure Vulnerability
- risk 0.42cvss 6.5epss 0.03
Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability
- risk 0.37cvss 5.7epss 0.01
Out-of-bounds read in Remote Desktop Client allows an authorized attacker to disclose information over a network.
- risk 0.35cvss 5.4epss 0.02
Remote Desktop Protocol Client Information Disclosure Vulnerability
Page 3 of 4