References https://nvd.nist.gov/vuln/detail/cve-2019-0708 https://devolutions.net/blog/tech-news-serious-vulnerability-found-in-microsoft-remote-desktop-client-cve-2025-48817/ https://www.sentinelone.com/vulnerability-database/cve-2024-49105/ https://ti.qianxin.com/advisory/articles/microsoft-windows-rdp-remote-desktop-services-multiple-remote-code-rxecution-vulnerability-notice/ https://windowsforum.com/threads/cve-2026-47654-client-side-rce-risk-in-windows-remote-desktop-connections.424392/ https://www.sentinelone.com/vulnerability-database/cve-2025-29966/ https://www.n-able.com/blog/patch-tuesday-may-2025-seven-zero-days-two-rdp-critical-vulns-and-microsoft-announces-extension-of-security-updates-for-m365-apps-until-2028 https://web.scut.edu.cn/_upload/article/files/7e/6c/f6ed2af94208835eb74b5a8e6745/7e20d571-1b27-45b0-8617-5a8373dc53f9.pdf https://community.spiceworks.com/t/serious-vulnerability-found-in-microsoft-remote-desktop-client-cve-2025-48817/1224801 https://www.tenable.com/plugins/nessus/234237
Related Vulnerabilities北京亿赛通科技发展有限责任公司电子文档安全管理系统CDGServer3-client存在前台sql漏洞PoCCVE-2026-57219: RabbitMQ Management - OAuth 2 Client Secret Disclosure智邦国际ERP /SYSN/json/pcclient/GetAllPrintTemplate.ashx SQL 注入漏洞AIClient2API /api/login 默认口令漏洞福建科立讯通信指挥调度管理平台 /api/client/fax/send_fax.php 命令执行漏洞PoCCVE-2026-33439: OpenAM <= 16.0.5 - Pre-Auth RCE via jato.clientSession DeserializationPoC孚盟云 CRM /m/Dingding/Card/ClientNameCard.aspx SQL 注入漏洞Apache CloudStack /client/api/ 默认口令漏洞Windows截图工具NTLM信息泄露漏洞(CVE-2026-33829)PoCCVE-2026-21643: Fortinet FortiClientEMS 7.4.4 - SQL InjectionPoCCVE-2026-35616: FortiClient EMS - Authentication BypassGradio /static//windows/win.ini 文件读取漏洞 (CVE-2026-28414)Windows Shell Link 敏感信息泄露与欺骗漏洞(CVE-2026-25185)