CVE-2025-48817
8.8Microsoft · Remote Desktop Client
A relative path traversal vulnerability in the Microsoft Remote Desktop Client permits an unauthorized attacker to execute arbitrary code over a network.
Executive summary
A critical relative path traversal vulnerability in Microsoft Remote Desktop Client allows unauthenticated attackers to achieve remote code execution, posing a severe risk to system integrity.
Vulnerability
The software is susceptible to a relative path traversal flaw, categorized under CWE-23, which enables an unauthenticated attacker to manipulate file paths and execute code within the context of the application.
Business impact
Successful exploitation of this vulnerability allows an attacker to execute arbitrary code with the privileges of the user running the Remote Desktop Client. This could lead to a complete compromise of the affected workstation, including unauthorized access to sensitive data, potential lateral movement within the corporate network, and significant operational disruption. Given the CVSS score of 8.8, this vulnerability is classified as high severity and requires immediate attention to prevent system takeover.
Remediation
Immediate Action: Apply the vendor security updates provided in the Microsoft Security Update Guide for CVE-2025-48817 to all affected Windows systems and Remote Desktop client installations.
Proactive Monitoring: Review system access logs for anomalous file path requests or unexpected process execution patterns originating from the Remote Desktop Client.
Compensating Controls: Ensure that Remote Desktop services are not exposed directly to the public internet, and utilize a Virtual Private Network (VPN) or Zero Trust Network Access (ZTNA) solution to gate access.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
The potential for remote code execution via a path traversal flaw necessitates urgent patching across all enterprise endpoints. IT administrators should prioritize the deployment of the identified security updates to all vulnerable versions of the Remote Desktop Client and Windows 10 builds. Failure to address this vulnerability exposes the organization to significant risk of unauthorized system control and data loss.
More Microsoft CVEs
Sources
- Remote Desktop Client Remote Code Execution Vulnerability Vendor advisory