Remote Desktop Client Remote Code Execution Vulnerability
Plan PatchCVSS 7.5CVE-2026-42909Jun 9, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionRequired
Summary
A race condition in Remote Desktop Client allows an unauthorized attacker to execute code over a network. The vulnerability stems from concurrent execution of shared resources with improper synchronization, enabling an attacker to inject code during the synchronization gap between resource access operations.
What this means
What could happen
An attacker could execute arbitrary code on computers running Remote Desktop Client by exploiting a race condition vulnerability, potentially allowing unauthorized access to system resources and data on affected machines.
Who's at risk
This affects any organization using Remote Desktop Client on Windows 10, Windows 11, or Windows Server systems (2016 through 2025). IT staff and engineers who use Remote Desktop for remote administration of industrial control systems, SCADA servers, or engineering workstations are at risk. Organizations running legacy Windows 10 Version 1607 or 1809 deployments should prioritize patching.
How it could be exploited
An attacker sends a specially crafted network request to the Remote Desktop Client. The race condition in the client allows the attacker to execute code during the synchronization window between shared resource access operations, gaining code execution on the victim's machine.
Prerequisites
- Network access to the target machine
- User interaction required (victim must trigger the vulnerable code path or be targeted via network communication)
- Remote Desktop Client must be present and active on the target system
remotely exploitableuser interaction requiredpatch available from vendor
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1WORKAROUNDRestrict network access to Remote Desktop ports (typically 3389) using firewall rules to allow only trusted administrative networks
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
HOTFIXApply Microsoft's June 2026 security update to your Windows operating system
HARDENINGDisable Remote Desktop Client on systems that do not require it for operational purposes
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/a2f62a07-de30-4263-a810-0d5e71954ad6Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.