PT-2025-42056 · Microsoft · Windows Remote Desktop Client+1
Published
2025-10-14
·
Updated
2026-03-25
·
CVE-2025-58718
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Microsoft Windows Remote Desktop Client (affected versions not specified)
Description
A use-after-free condition exists in the Remote Desktop Client (RDC) component of Microsoft Windows. This issue allows a remote attacker to execute arbitrary code. A use-after-free occurs when a program attempts to access memory after it has been freed, leading to unpredictable behavior. Exploitation involves manipulating the application's memory management within the Remote Desktop Client, which handles remote connections. The vulnerability could allow an unauthorized attacker to execute code over a network.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
RCE
Use After Free
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Windows Remote Desktop Client
Windows