Windows App Microsoft Windows App

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Microsoft Windows App.

Recent Microsoft Windows App Security Advisories

Advisory Title Published
CVE-2026-21517 CVE-2026-21517 Windows App for Mac Installer Elevation of Privilege Vulnerability February 10, 2026
CVE-2025-48820 CVE-2025-48820 Windows AppX Deployment Service Elevation of Privilege Vulnerability July 8, 2025
CVE-2025-33069 CVE-2025-33069 Windows App Control for Business Security Feature Bypass Vulnerability June 10, 2025
CVE-2025-21275 CVE-2025-21275 Windows App Package Installer Elevation of Privilege Vulnerability January 14, 2025
CVE-2024-38177 CVE-2024-38177 Windows App Installer Spoofing Vulnerability August 13, 2024
CVE-2022-24549 Windows AppX Package Manager Elevation of Privilege Vulnerability April 12, 2022
CVE-2022-21860 Windows AppContracts API Server Elevation of Privilege Vulnerability January 11, 2022
CVE-2022-21862 Windows Application Model Core API Elevation of Privilege Vulnerability January 11, 2022
CVE-2021-43890 Windows AppX Installer Spoofing Vulnerability December 14, 2021
CVE-2021-40476 Windows AppContainer Elevation Of Privilege Vulnerability October 12, 2021

By the Year

In 2026 there have been 0 vulnerabilities in Microsoft Windows App. Last year, in 2025 Windows App had 5 security vulnerabilities published. Right now, Windows App is on track to have less security vulnerabilities in 2026 than it did last year.

Year Vulnerabilities Average Score
2026 0 0.00
2025 5 8.18
2024 1 8.40

It may take a day or so for new Windows App vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Microsoft Windows App Security Vulnerabilities

Jul 2025: Remote Desktop Client Remote Code Execution Vulnerability
CVE-2025-48817 8.8 - High - July 08, 2025

Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Relative Path Traversal

Jun 2025: Remote Desktop Protocol Client Information Disclosure Vulnerability
CVE-2025-32715 6.5 - Medium - June 10, 2025

Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.

Out-of-bounds Read

May 2025: Remote Desktop Client Remote Code Execution Vulnerability
CVE-2025-29966 8.8 - High - May 13, 2025

Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network.

Heap-based Buffer Overflow

Apr 2025: Remote Desktop Client Remote Code Execution Vulnerability
CVE-2025-27487 8 - High - April 08, 2025

Heap-based buffer overflow in Remote Desktop Client allows an authorized attacker to execute code over a network.

Heap-based Buffer Overflow

Mar 2025: Remote Desktop Client Remote Code Execution Vulnerability
CVE-2025-26645 8.8 - High - March 11, 2025

Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

Relative Path Traversal

Microsoft Remote Desktop Client RCE - CVE-2024-49105
CVE-2024-49105 8.4 - High - December 12, 2024

Remote Desktop Client Remote Code Execution Vulnerability

Authorization

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Microsoft Windows App or by Microsoft? Click the Watch button to subscribe.

Microsoft
Vendor

subscribe