Impact
An improper control of code generation in Microsoft Remote Desktop Client allows an unauthorized attacker to inject and execute malicious code over a network. This can lead to full compromise of the host system, including loss of confidentiality, integrity, and availability.
Affected Systems
Microsoft Remote Desktop client for Windows Desktop. Exact product edition and version details are not specified; all unpatched instances of the client are potentially vulnerable.
Risk and Exploitability
The vulnerability receives a CVSS score of 8.8, indicating high severity. The EPSS score is not available, which provides no current exploitation probability data, yet the risk remains significant. It is not listed in the CISA KEV catalog. The likely attack vector requires the victim to have the Remote Desktop client running and reachable over a network; the attacker can send specially crafted data that triggers code injection.
OpenCVE Enrichment