Home
Description
Missing authorization in Remote Desktop Server allows an unauthorized attacker to perform spoofing over a network.
PUBLISHED Reserved 2025-06-13 | Published 2025-08-12 | Updated 2025-09-17 | Assigner microsoft
CRITICAL: 9.1CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N/E:U/RL:O/RC:C
Problem types
CWE-862: Missing Authorization
Product status
10.0.20348.0 before 10.0.20348.4052
affected
10.0.19044.0 before 10.0.19044.6216
affected
10.0.22621.0 before 10.0.22621.5768
affected
10.0.19045.0 before 10.0.19045.6216
affected
10.0.26100.0 before 10.0.26100.4946
affected
10.0.22631.0 before 10.0.22631.5768
affected
10.0.22631.0 before 10.0.22631.5768
affected
10.0.25398.0 before 10.0.25398.1791
affected
10.0.26100.0 before 10.0.26100.4946
affected
10.0.26100.0 before 10.0.26100.4946
affected
References
msrc.microsoft.com/update-guide/vulnerability/CVE-2025-50171 (Remote Desktop Spoofing Vulnerability) vendor-advisory
cve.org
(CVE-2025-50171)
nvd.nist.gov
(CVE-2025-50171)
Download JSON