Dec 2024: Remote Desktop Client Remote Code Execution Vulnerability
CVE-2024-49105 Published on December 12, 2024
Remote Desktop Client Remote Code Execution Vulnerability
Remote Desktop Client Remote Code Execution Vulnerability
Weakness Type
What is an Authorization Vulnerability?
The software does not restrict or incorrectly restricts access to a resource from an unauthorized actor.
CVE-2024-49105 has been classified to as an Authorization vulnerability or weakness.
Products Associated with CVE-2024-49105
Want to know whenever a new CVE is published for Microsoft products? stack.watch will email you.
Affected Versions
Microsoft Remote Desktop client for Windows Desktop:- Version 1.2.0.0 and below 1.2.5716.0 is affected.
- Version 10.0.10240.0 and below 10.0.10240.20857 is affected.
- Version 10.0.14393.0 and below 10.0.14393.7606 is affected.
- Version 10.0.17763.0 and below 10.0.17763.6659 is affected.
- Version 10.0.19043.0 and below 10.0.19044.5247 is affected.
- Version 10.0.19045.0 and below 10.0.19045.5247 is affected.
- Version 10.0.22621.0 and below 10.0.22621.4602 is affected.
- Version 10.0.22631.0 and below 10.0.22631.4602 is affected.
- Version 10.0.22631.0 and below 10.0.22631.4602 is affected.
- Version 10.0.26100.0 and below 10.0.26100.2605 is affected.
- Version 1.00 and below 2.0.327.0 is affected.
- Version 6.1.7601.0 and below 6.1.7601.27467 is affected.
- Version 6.1.7601.0 and below 6.1.7601.27467 is affected.
- Version 6.2.9200.0 and below 6.2.9200.25222 is affected.
- Version 6.2.9200.0 and below 6.2.9200.25222 is affected.
- Version 6.3.9600.0 and below 6.3.9600.22318 is affected.
- Version 6.3.9600.0 and below 6.3.9600.22318 is affected.
- Version 10.0.14393.0 and below 10.0.14393.7606 is affected.
- Version 10.0.14393.0 and below 10.0.14393.7606 is affected.
- Version 10.0.17763.0 and below 10.0.17763.6659 is affected.
- Version 10.0.17763.0 and below 10.0.17763.6659 is affected.
- Version 10.0.20348.0 and below 10.0.20348.2966 is affected.
- Version 10.0.25398.0 and below 10.0.25398.1308 is affected.
- Version 10.0.26100.0 and below 10.0.26100.2605 is affected.
- Version 10.0.26100.0 and below 10.0.26100.2605 is affected.
Exploit Probability
EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.