CVE-2023-29362 is a Remote Code Execution (RCE) vulnerability affecting Microsoft's Remote Desktop Client. This high-severity flaw (CVSS 8.8) allows an unauthenticated attacker to execute arbitrary code on a vulnerable system through a low-complexity network attack, requiring user interaction. While the vulnerability has a high potential impact (confidentiality, integrity, and availability), there is currently no public exploit code available, nor is it listed in CISA's KEV catalog, suggesting it is not actively exploited in the wild. Community discussion and media coverage are minimal, though it was noted in Microsoft's June 2023 Patch Tuesday.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.2.4337CPE matchmatch criteria | cpe:2.3:a:microsoft:remote_desktop_client:*:*:*:*:*:windows:*:* | ||
< 10.0.10240.19983CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1507:*:*:*:*:*:*:x64:* | ||
< 10.0.14393.5989CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1607:*:*:*:*:*:*:x64:* | ||
< 10.0.17763.4499CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_1809:*:*:*:*:*:*:x64:* | ||
< 10.0.14393.5989CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_10_21h2:*:*:*:*:*:*:x64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.