980
VMScore

CVE-2025-26645

CVSSv4: NA | CVSSv3: 8.8 | CVSSv2: NA | VMScore: 980 | EPSS: 0.00374 | KEV: Not Included
Published: 11/03/2025 Updated: 11/03/2025

Vulnerability Summary

Remote Desktop Client Relative Path Traversal Enables Unauthorized Code Execution

Relative path traversal in Remote Desktop Client allows an unauthorized malicious user to execute code over a network.

Vulnerability Trend

Recent Articles

Microsoft March 2025 Patch Tuesday fixes 7 zero-days, 57 flaws
BleepingComputer • Lawrence Abrams • 11 Mar 2025

Microsoft March 2025 Patch Tuesday fixes 7 zero-days, 57 flaws By Lawrence Abrams March 11, 2025 01:45 PM 2 .crit { font-weight:bold; color:red; } .article_section td { font-size: 14px!important; } Today is Microsoft's March 2025 Patch Tuesday, which includes security updates for 57 flaws, including six actively exploited zero-day vulnerabilities. This Patch Tuesday also fixes six "Critical" vulnerabilities, all remote code execution vulnerabilities. The number of bugs in each vulnerability...

Choose your own Patch Tuesday adventure: Start with six zero-day fixes, or six critical flaws
The Register

Topics Security Off-Prem On-Prem Software Offbeat Special Features Vendor Voice Vendor Voice Resources Microsoft tackles 50-plus security blunders, Adobe splats 3D bugs, and Apple deals with a doozy

Patch Tuesday Microsoft’s Patch Tuesday bundle has appeared, with a dirty dozen flaws competing for your urgent attention – six of them rated critical and another six already being exploited by criminals. Let’s start with the six already exploited vulnerabilities, three of which impact Windows NTFS. The first is CVE-2025-24993 - a heap-based buffer overflow in NTFS used by Windows Server 2008 and later systems, as well as Windows 10 and 11. The flaw makes remote code execution (RCE) a poss...