This page lists publicly disclosed CVE vulnerabilities affecting microsoft windows_app (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2026-47289 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | [email protected] | 8.8 | 0.47% | 2026-06-09 | 2026-06-12 |
| CVE-2026-44801 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | [email protected] | 7.5 | 0.36% | 2026-06-09 | 2026-06-12 |
| CVE-2026-44799 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | [email protected] | 7.5 | 0.37% | 2026-06-09 | 2026-06-15 |
| CVE-2026-42992 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | [email protected] | 7.5 | 0.37% | 2026-06-09 | 2026-06-15 |
| CVE-2026-42985 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | [email protected] | 8.8 | 0.50% | 2026-06-09 | 2026-06-15 |
| CVE-2026-42909 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | [email protected] | 7.5 | 0.32% | 2026-06-09 | 2026-06-15 |
| CVE-2026-23656 | Insufficient verification of data authenticity in Windows App Installer allows an unauthorized attacker to perform spoofing over a network. | [email protected] | 5.9 | 0.30% | 2026-03-10 | 2026-03-12 |
| CVE-2026-21517 | Improper link resolution before file access ('link following') in Windows App for Mac allows an authorized attacker to elevate privileges locally. | [email protected] | 4.7 | 0.36% | 2026-02-10 | 2026-02-25 |
| CVE-2025-58718 | Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | [email protected] | 8.8 | 0.56% | 2025-10-14 | 2025-10-31 |
| CVE-2025-48817 | Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | [email protected] | 8.8 | 0.94% | 2025-07-08 | 2025-07-15 |
| CVE-2025-32715 | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | [email protected] | 6.5 | 1.24% | 2025-06-10 | 2025-07-07 |
| CVE-2025-29966 | Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network. | [email protected] | 8.8 | 1.12% | 2025-05-13 | 2025-05-19 |
| CVE-2025-27487 | Heap-based buffer overflow in Remote Desktop Client allows an authorized attacker to execute code over a network. | [email protected] | 8.0 | 1.26% | 2025-04-08 | 2025-07-07 |
| CVE-2025-26645 | Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | [email protected] | 8.8 | 3.23% | 2025-03-11 | 2025-07-07 |
| CVE-2024-49105 | Remote Desktop Client Remote Code Execution Vulnerability | [email protected] | 8.4 | 1.48% | 2024-12-12 | 2025-07-07 |
| CVE-2020-0919 | An elevation of privilege vulnerability exists in Remote Desktop App for Mac in the way it allows an attacker to load unsigned binaries, aka 'Microsoft Remote Desktop App for Mac Elevation of Privilege Vulnerability'. | [email protected] | 7.8 | 0.74% | 2020-04-15 | 2026-02-12 |