Remote Desktop Client Remote Code Execution Vulnerability

Plan PatchCVSS 7.5CVE-2026-42913Jun 9, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionRequired
Summary

A race condition in Remote Desktop Client allows an unauthorized attacker to execute arbitrary code over a network. The vulnerability occurs due to concurrent execution using a shared resource with improper synchronization.

What this means
What could happen
An attacker could run arbitrary code on a Windows workstation or server through Remote Desktop Client, potentially gaining control of engineering workstations, HMI systems, or servers that manage OT networks.
Who's at risk
Water authorities and utilities operating Windows-based engineering workstations, HMI systems, and administrative servers that use Remote Desktop Client for remote management should prioritize patching. This affects any staff connecting to or hosting Remote Desktop sessions on Windows Server 2022, Windows Server 2025, or Windows 11 systems.
How it could be exploited
An attacker sends a specially crafted network request to a system running vulnerable Remote Desktop Client. By exploiting the race condition in shared resource handling, the attacker can execute arbitrary code on the target system without authentication. This could compromise engineering workstations connected to OT networks.
Prerequisites
  • Network access to a system running vulnerable Remote Desktop Client
  • User interaction with malicious network request or connection attempt
remotely exploitableuser interaction requiredaffects management and engineering systems
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (12)
12 with fix
ProductAffected VersionsFix Status
Windows Server 2022All versionsBuild 10.0.20348.5256
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5256
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.32995
Windows 11 Version 25H2 for ARM64-based SystemsAll versionsBuild 10.0.26200.8655
Windows 11 Version 25H2 for x64-based SystemsAll versionsBuild 10.0.26200.8655
Windows 11 Version 23H2 for ARM64-based SystemsAll versionsBuild 10.0.22631.7219
Windows 11 Version 23H2 for x64-based SystemsAll versionsBuild 10.0.22631.7219
Windows 11 Version 24H2 for ARM64-based SystemsAll versionsBuild 10.0.26100.8655
Remediation & Mitigation
0/3
Do now
0/1
WORKAROUNDDisable Remote Desktop Client on systems that do not require it
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the June 2026 Windows security update on all Windows Server and Windows 11 systems
Long-term hardening
0/1
HARDENINGRestrict network access to Remote Desktop services to engineering workstations and authorized administrative access points only
API: /api/v1/advisories/b5fb5650-7c7f-42e9-9a5e-0c257ac96cec

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.