CVE-2025-29966: Remote Desktop Client Remote Code Execution Vulnerability
Heap-based buffer overflow in Windows Remote Desktop allows an unauthorized attacker to execute code over a network.
Other sources
Remote Desktop Client Remote Code Execution Vulnerability
— Microsoft
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-29966?
CVE-2025-29966 has been classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2025-29966?
To fix CVE-2025-29966, ensure that your affected Microsoft products are updated with the latest security patches provided.
What products are affected by CVE-2025-29966?
CVE-2025-29966 affects various versions of Windows and Windows Server, including Windows 10, 11, and Windows Server 2022.
What type of attack does CVE-2025-29966 enable?
CVE-2025-29966 allows an unauthorized attacker to execute arbitrary code over a network using a heap-based buffer overflow.
Is there a workaround for CVE-2025-29966 if I cannot apply the patch immediately?
Temporary workarounds for CVE-2025-29966 may include disabling the Remote Desktop feature or limiting access to affected systems.