Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
widely-deployed-product-advisoryendpoint-software-vulnerabilityinternet-facing-service-vulnerability

Microsoft Discloses Remote Code Execution Flaws in Remote Desktop and RPC Components

Updated 28d agoFirst seen May 25, 20264 sources

Microsoft published security advisories for multiple remote code execution vulnerabilities affecting Remote Desktop Client, Remote Desktop Protocol, and the Remote Procedure Call (RPC) Runtime. The referenced issues include CVE-2025-58718 in the Remote Desktop Client, alongside earlier Microsoft advisories for CVE-2022-21851 in the Remote Desktop Client, CVE-2022-21893 in Remote Desktop Protocol, and CVE-2022-21922 in the RPC Runtime.

The advisories indicate continued security risk around core Windows remote access and interprocess communication components that are widely used in enterprise environments. For defenders, the common thread is exposure to remote code execution in services and clients tied to remote connectivity, making Microsoft’s security updates for these CVEs a priority for systems that rely on RDP and RPC functionality.

Share:
Microsoft Discloses Remote Code Execution Flaws in Remote Desktop and RPC Components
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

2 events from the most recent confirmed update back to the earliest known activity.

2 EVENTS
Oct 14, 20258mo ago

Microsoft publishes advisory for CVE-2025-58718

Microsoft added CVE-2025-58718 to its Security Update Guide as a Remote Desktop Client remote code execution vulnerability.

Jan 11, 20224y ago

Microsoft publishes fixes for three January 2022 RCE vulnerabilities

Microsoft released Security Update Guide advisories for CVE-2022-21851, CVE-2022-21893, and CVE-2022-21922, covering remote code execution flaws in Remote Desktop Client, Remote Desktop Protocol, and Remote Procedure Call Runtime respectively.

The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Microsoft Discloses Remote Code Execution Flaws in Remote Desktop and RPC Components | Mallory