Microsoft Remote Desktop Client — known CVE vulnerabilities
Every CVE whose affected-product data names Microsoft Remote Desktop Client, ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (30)
CVE-2025-26645 — CVSS 8.8 (high): Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-78463 — CVSS 8.8 (high): Improper control of generation of code ('code injection') in Remote Desktop Client allows an unauthorized attacker to execute code over a…
CVE-2026-42985 — CVSS 8.8 (high): Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-32157 — CVSS 8.8 (high): Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2025-58718 — CVSS 8.8 (high): Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2025-48817 — CVSS 8.8 (high): Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2025-27487 — CVSS 8.0 (high): Heap-based buffer overflow in Remote Desktop Client allows an authorized attacker to execute code over a network.
CVE-2019-0887 — CVSS 8.0 (high): A remote code execution vulnerability exists in Remote Desktop Services - formerly known as Terminal Services - when an authenticated…
CVE-2026-57098 — CVSS 7.5 (high): Improper verification of cryptographic signature in Windows RDP Client allows an unauthorized attacker to disclose information over a…
CVE-2026-45639 — CVSS 7.5 (high): Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
CVE-2026-44799 — CVSS 7.5 (high): Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2026-42909 — CVSS 7.5 (high): Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized…
CVE-2026-42913 — CVSS 7.5 (high): Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized…
CVE-2026-44801 — CVSS 7.5 (high): Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
CVE-2025-32715 — CVSS 6.5 (medium): Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.