Remote Desktop Client Remote Code Execution Vulnerability
Plan PatchCVSS 7.5CVE-2026-42913Jun 9, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionRequired
Summary
A race condition in Remote Desktop Client allows an unauthorized attacker to execute arbitrary code over a network. The vulnerability occurs due to concurrent execution using a shared resource with improper synchronization.
What this means
What could happen
An attacker could run arbitrary code on a Windows workstation or server through Remote Desktop Client, potentially gaining control of engineering workstations, HMI systems, or servers that manage OT networks.
Who's at risk
Water authorities and utilities operating Windows-based engineering workstations, HMI systems, and administrative servers that use Remote Desktop Client for remote management should prioritize patching. This affects any staff connecting to or hosting Remote Desktop sessions on Windows Server 2022, Windows Server 2025, or Windows 11 systems.
How it could be exploited
An attacker sends a specially crafted network request to a system running vulnerable Remote Desktop Client. By exploiting the race condition in shared resource handling, the attacker can execute arbitrary code on the target system without authentication. This could compromise engineering workstations connected to OT networks.
Prerequisites
- Network access to a system running vulnerable Remote Desktop Client
- User interaction with malicious network request or connection attempt
remotely exploitableuser interaction requiredaffects management and engineering systems
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1WORKAROUNDDisable Remote Desktop Client on systems that do not require it
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply the June 2026 Windows security update on all Windows Server and Windows 11 systems
Long-term hardening
0/1HARDENINGRestrict network access to Remote Desktop services to engineering workstations and authorized administrative access points only
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/b5fb5650-7c7f-42e9-9a5e-0c257ac96cecGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.