MEDIUM · 5.4

CVE-2022-24503

Remote Desktop Protocol Client Information Disclosure Vulnerability

Vulnerability Description

Remote Desktop Protocol Client Information Disclosure Vulnerability

CVSS Score

5.4

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
REQUIRED
Scope
UNCHANGED
Confidentiality
LOW
Integrity
NONE
Availability
LOW

Affected Products

VendorProductVersions
MicrosoftRemote Desktop Client< 1.2.2925
MicrosoftWindows 10All versions
MicrosoftWindows 11-
MicrosoftWindows 7-
MicrosoftWindows 8.1All versions
MicrosoftWindows Rt 8.1All versions
MicrosoftWindows Server20h2
MicrosoftWindows Server 2008r2
MicrosoftWindows Server 2012-
MicrosoftWindows Server 2016-
MicrosoftWindows Server 2019-
MicrosoftWindows Server 2022-

References

FAQ

What is CVE-2022-24503?

CVE-2022-24503 is a vulnerability with a CVSS score of 5.4 (MEDIUM). Remote Desktop Protocol Client Information Disclosure Vulnerability

How severe is CVE-2022-24503?

CVE-2022-24503 has been rated MEDIUM with a CVSS base score of 5.4/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-24503?

Check the references section above for vendor advisories and patch information. Affected products include: Microsoft Remote Desktop Client, Microsoft Windows 10, Microsoft Windows 11, Microsoft Windows 7, Microsoft Windows 8.1.