Remote Desktop Client Remote Code Execution Vulnerability

Plan PatchCVSS 7.5CVE-2026-42909Jun 9, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionRequired
Summary

A race condition in Remote Desktop Client allows an unauthorized attacker to execute code over a network. The vulnerability stems from concurrent execution of shared resources with improper synchronization, enabling an attacker to inject code during the synchronization gap between resource access operations.

What this means
What could happen
An attacker could execute arbitrary code on computers running Remote Desktop Client by exploiting a race condition vulnerability, potentially allowing unauthorized access to system resources and data on affected machines.
Who's at risk
This affects any organization using Remote Desktop Client on Windows 10, Windows 11, or Windows Server systems (2016 through 2025). IT staff and engineers who use Remote Desktop for remote administration of industrial control systems, SCADA servers, or engineering workstations are at risk. Organizations running legacy Windows 10 Version 1607 or 1809 deployments should prioritize patching.
How it could be exploited
An attacker sends a specially crafted network request to the Remote Desktop Client. The race condition in the client allows the attacker to execute code during the synchronization window between shared resource access operations, gaining code execution on the victim's machine.
Prerequisites
  • Network access to the target machine
  • User interaction required (victim must trigger the vulnerable code path or be targeted via network communication)
  • Remote Desktop Client must be present and active on the target system
remotely exploitableuser interaction requiredpatch available from vendor
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.8880
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.8880
Windows Server 2019All versionsBuild 10.0.17763.8880
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.8880
Windows Server 2022All versionsBuild 10.0.20348.5256
Remediation & Mitigation
0/3
Do now
0/1
WORKAROUNDRestrict network access to Remote Desktop ports (typically 3389) using firewall rules to allow only trusted administrative networks
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

HOTFIXApply Microsoft's June 2026 security update to your Windows operating system
HARDENINGDisable Remote Desktop Client on systems that do not require it for operational purposes
API: /api/v1/advisories/a2f62a07-de30-4263-a810-0d5e71954ad6

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Remote Desktop Client Remote Code Execution Vulnerability | CVSS 7.5 - OTPulse