CVE-2015-2373: Microsoft Windows 7

High severity, CVSS 10.0. EPSS: 38.1% chance of exploitation in the next 30 days.

The Remote Desktop Protocol (RDP) server service in Microsoft Windows 7 SP1, Windows 8, and Windows Server 2012 allows remote attackers to execute arbitrary code via a series of crafted packets, aka "Remote Desktop Protocol (RDP) Remote Code Execution Vulnerability."

Affected products

  • Microsoft Windows 7: any version
  • Microsoft Windows 8: affected versions not specified
  • Microsoft Windows Server 2012: affected versions not specified

Published 2015-07-14. Last modified 2026-06-17.