Reported risk: A patch was released for a critical remote code execution vulnerability in remote desktop services. This vulnerability can be exploited remotely without authentication on certain operating systems. An attacker who successfully exploited this vulnerability could execute arbitrary code on the target system; then install programs; view, change, or delete data; or create new accounts with full user rights. If the vulnerability could be exploited locally, it would lock down the computer.
Verify each fact at the issuing agency before acting. Recall scope, affected lots, and remediation instructions may be updated by the agency after our last sync.
ProductGuru indexes recall and safety-alert records from ~30 public agency registries. We are not lawyers, regulators or product-safety consultants. This page restates what the named agency published; consult the primary source above (or qualified counsel in your jurisdiction) before any commercial, medical or safety decision.