CVE-2025-58718
8.8Microsoft · Remote Desktop Client
A use-after-free vulnerability in the Microsoft Remote Desktop Client allows an unauthenticated, remote attacker to execute arbitrary code on the target system.
Executive summary
A critical use-after-free vulnerability in Microsoft Remote Desktop Client enables remote code execution by an unauthenticated attacker, posing a severe risk to system integrity.
Vulnerability
This flaw is a use-after-free vulnerability (CWE-416) within the Remote Desktop Client, which can be triggered by an unauthenticated attacker over the network to achieve remote code execution.
Business impact
Successful exploitation of this vulnerability allows an attacker to gain full control over the affected system, potentially leading to unauthorized data access, lateral movement within the network, and complete system compromise. Given the CVSS score of 8.8, this vulnerability represents a high-severity threat that could lead to significant operational disruption and data loss if exploited.
Remediation
Immediate Action: Apply the relevant security updates provided by Microsoft for the Remote Desktop Client and the affected Windows 10 versions immediately.
Proactive Monitoring: Monitor network traffic and endpoint logs for abnormal Remote Desktop Protocol (RDP) connection patterns or unexpected process execution originating from the RDP client service.
Compensating Controls: Restrict access to RDP services to trusted internal networks or require a Virtual Private Network (VPN) with multi-factor authentication to limit the exposure of the service to the public internet.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Organizations should prioritize the deployment of the vendor-provided patches across all affected Windows environments to eliminate this vulnerability. Given the capability for remote code execution, delaying remediation increases the risk of successful exploitation by malicious actors. Ensure that all systems are updated to the non-vulnerable build versions as specified in the Microsoft security update guide.
More Microsoft CVEs
Sources
- Remote Desktop Client Remote Code Execution Vulnerability Vendor advisory