Remote Desktop Client RCE via crafted .rdp
CVE-2023-24905 Published on May 9, 2023
Remote Desktop Client Remote Code Execution Vulnerability
Remote Desktop Client Remote Code Execution Vulnerability
Weakness Type
What is an Authorization Vulnerability?
The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVE-2023-24905 has been classified to as an Authorization vulnerability or weakness.
Products Associated with CVE-2023-24905
Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.
Affected Versions
Microsoft Windows 10 Version 20H2:- Version 10.0.0 and below 10.0.19042.2965 is affected.
- Version 10.0.0 and below 10.0.22000.1936 is affected.
- Version 10.0.19043.0 and below 10.0.19044.2965 is affected.
- Version 10.0.22621.0 and below 10.0.22621.1702 is affected.
- Version 10.0.19045.0 and below 10.0.19045.2965 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.