Microsoft
Microsoft Remote Desktop Client: vulnerabilidades y CVE
Microsoft Remote Desktop Client tiene 30 vulnerabilidades publicadas, 12 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE30
Últimos 12 meses12
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-80077 | Alta (8.8) | 0.82% | — | 8 sept 2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
| CVE-2026-80074 | Alta (8.8) | 0.82% | — | 8 sept 2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
| CVE-2026-78463 | Alta (8.8) | 0.86% | — | 8 sept 2026 | Improper control of generation of code ('code injection') in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
| CVE-2026-57098 | Alta (7.5) | 0.64% | — | 8 sept 2026 | Improper verification of cryptographic signature in Windows RDP Client allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-45639 | Alta (7.5) | 1.0% | — | 9 jun 2026 | Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-44801 | Alta (7.5) | 0.61% | — | 9 jun 2026 | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
| CVE-2026-44799 | Alta (7.5) | 0.61% | — | 9 jun 2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
| CVE-2026-42985 | Alta (8.8) | 0.82% | — | 9 jun 2026 | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
| CVE-2026-42913 | Alta (7.5) | 0.47% | — | 9 jun 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
| CVE-2026-42909 | Alta (7.5) | 0.47% | — | 9 jun 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
| CVE-2026-32157 | Alta (8.8) | 0.82% | — | 14 abr 2026 | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
| CVE-2025-58718 | Alta (8.8) | 0.60% | — | 14 oct 2025 | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
| CVE-2025-48817 | Alta (8.8) | 1.0% | — | 8 jul 2025 | Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
| CVE-2025-32715 | Media (6.5) | 1.4% | — | 10 jun 2025 | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. |
| CVE-2025-27487 | Alta (8) | 1.5% | — | 8 abr 2025 | Heap-based buffer overflow in Remote Desktop Client allows an authorized attacker to execute code over a network. |
| CVE-2025-26645 | Alta (8.8) | 3.1% | — | 11 mar 2025 | Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
| CVE-2024-49105 | Alta (8.4) | 1.5% | — | 12 dic 2024 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2024-38131 | Alta (8.8) | 1.3% | — | 13 ago 2024 | Clipboard Virtual Channel Extension Remote Code Execution Vulnerability |
| CVE-2023-29362 | Alta (8.8) | 1.3% | — | 14 jun 2023 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2023-29352 | Media (6.5) | 1.2% | — | 14 jun 2023 | Windows Remote Desktop Security Feature Bypass Vulnerability |
| CVE-2023-28267 | Media (6.5) | 2.1% | — | 11 abr 2023 | Remote Desktop Protocol Client Information Disclosure Vulnerability |
| CVE-2022-41121 | Alta (7.8) | 1.1% | — | 13 dic 2022 | Windows Graphics Component Elevation of Privilege Vulnerability |
| CVE-2022-26940 | Media (6.5) | 2.7% | — | 10 may 2022 | Remote Desktop Protocol Client Information Disclosure Vulnerability |
| CVE-2022-22017 | Alta (8.8) | 37% | — | 10 may 2022 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2022-22015 | Media (6.5) | 2.7% | — | 10 may 2022 | Windows Remote Desktop Protocol (RDP) Information Disclosure Vulnerability |
| CVE-2022-24503 | Media (5.3) | 2.4% | — | 9 mar 2022 | Remote Desktop Protocol Client Information Disclosure Vulnerability |
| CVE-2021-38665 | Media (6.5) | 7.0% | — | 10 nov 2021 | Remote Desktop Protocol Client Information Disclosure Vulnerability |
| CVE-2021-34535 | Alta (8.8) | 22% | — | 12 ago 2021 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2021-1669 | Alta (8.8) | 3.0% | — | 12 ene 2021 | Windows Remote Desktop Security Feature Bypass Vulnerability |
| CVE-2019-0887 | Alta (8) | 71% | — | 15 jul 2019 | A remote code execution vulnerability exists in Remote Desktop Services - formerly known as Terminal Services - when an authenticated attacker abuses clipboard redirection, aka 'Remote Desktop Services Remote Code… |