CVE-2025-29966 · Microsoft
Microsoft Windows RDP Remote Code Execution
- Severity:
- Critical
- CVSS:
- 9.8
- Published:
- May 12, 2025
Summary
A memory corruption flaw in the Remote Desktop client allows a malicious server to run code on a connecting machine without user interaction.
Affected products
Windows 10, Windows 11, Windows Server 2019 and 2022 RDP client components.
Impact
Full remote code execution in the context of the connecting user, enabling lateral movement.
Recommended action
Apply the May 2025 cumulative update, restrict outbound RDP, and monitor for unusual client connections.
Need clarity fast?
Whether you're a website owner, product team, or business leader, we'll expertly help you investigate, assess, and secure what matters most.
- 24/7 secure intake
- Confidential and discreet
- Rapid expert response
We respect your privacy. No spam. Ever. Or email support@techforensiq.com