Microsoft
Microsoft Windows APP: vulnerabilidades y CVE
Microsoft Windows APP tiene 21 vulnerabilidades publicadas, 14 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE21
Últimos 12 meses14
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-69550 | Media (6.5) | 0.92% | — | 19 ago 2026 | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-59133 | Alta (8.8) | 0.91% | — | 11 ago 2026 | Execution with unnecessary privileges in Microsoft High Performance Computing (HPC) Pack allows an authorized attacker to elevate privileges over a network. |
| CVE-2026-59124 | Crítica (9.8) | 1.5% | — | 11 ago 2026 | Deserialization of untrusted data in Microsoft High Performance Computing (HPC) Pack allows an unauthorized attacker to execute code over a network. |
| CVE-2026-47289 | Alta (8.8) | 0.82% | — | 9 jun 2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
| CVE-2026-45639 | Alta (7.5) | 1.0% | — | 9 jun 2026 | Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-44801 | Alta (7.5) | 0.61% | — | 9 jun 2026 | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
| CVE-2026-44799 | Alta (7.5) | 0.61% | — | 9 jun 2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
| CVE-2026-42992 | Alta (7.5) | 0.61% | — | 9 jun 2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
| CVE-2026-42985 | Alta (8.8) | 0.82% | — | 9 jun 2026 | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
| CVE-2026-42909 | Alta (7.5) | 0.47% | — | 9 jun 2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
| CVE-2026-42908 | Alta (7.5) | 1.0% | — | 9 jun 2026 | Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network. |
| CVE-2026-23656 | Media (5.9) | 0.30% | — | 10 mar 2026 | Insufficient verification of data authenticity in Windows App Installer allows an unauthorized attacker to perform spoofing over a network. |
| CVE-2026-21517 | Alta (7) | 0.38% | — | 10 feb 2026 | Improper link resolution before file access ('link following') in Windows App for Mac allows an authorized attacker to elevate privileges locally. |
| CVE-2025-58718 | Alta (8.8) | 0.60% | — | 14 oct 2025 | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
| CVE-2025-48817 | Alta (8.8) | 1.0% | — | 8 jul 2025 | Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
| CVE-2025-32715 | Media (6.5) | 1.4% | — | 10 jun 2025 | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. |
| CVE-2025-29966 | Alta (8.8) | 1.4% | — | 13 may 2025 | Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network. |
| CVE-2025-27487 | Alta (8) | 1.5% | — | 8 abr 2025 | Heap-based buffer overflow in Remote Desktop Client allows an authorized attacker to execute code over a network. |
| CVE-2025-26645 | Alta (8.8) | 3.1% | — | 11 mar 2025 | Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network. |
| CVE-2024-49105 | Alta (8.4) | 1.5% | — | 12 dic 2024 | Remote Desktop Client Remote Code Execution Vulnerability |
| CVE-2020-0919 | Alta (7.8) | 0.79% | — | 15 abr 2020 | An elevation of privilege vulnerability exists in Remote Desktop App for Mac in the way it allows an attacker to load unsigned binaries, aka 'Microsoft Remote Desktop App for Mac Elevation of Privilege Vulnerability'. |