PT-2025-42056 · Microsoft · Windows Remote Desktop Client+1

Published

2025-10-14

·

Updated

2026-03-25

·

CVE-2025-58718

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Microsoft Windows Remote Desktop Client (affected versions not specified)
Description A use-after-free condition exists in the Remote Desktop Client (RDC) component of Microsoft Windows. This issue allows a remote attacker to execute arbitrary code. A use-after-free occurs when a program attempts to access memory after it has been freed, leading to unpredictable behavior. Exploitation involves manipulating the application's memory management within the Remote Desktop Client, which handles remote connections. The vulnerability could allow an unauthorized attacker to execute code over a network.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Use After Free

Weakness Enumeration

Related Identifiers

BDU:2025-13277
CVE-2025-58718

Affected Products

Windows Remote Desktop Client
Windows