Remote Desktop Client Remote Code Execution Vulnerability

Plan PatchCVSS 8.8CVE-2026-42985Jun 9, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary

Use-after-free vulnerability in Remote Desktop Client allows an unauthorized attacker to execute code over a network on affected Windows systems. The vulnerability affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (all versions), and Windows Server 2016, 2019, 2022, and 2025. Vendor assessment indicates exploitation is more likely and urges immediate application of the June 2026 security update.

What this means
What could happen
An attacker could execute arbitrary code on Windows systems running Remote Desktop Client by sending a specially crafted network message, potentially allowing them to take full control of the machine. This could enable them to access sensitive data, modify configurations, or disrupt operations if the system is used for critical infrastructure management.
Who's at risk
This affects IT and OT staff who use Remote Desktop Client to manage Windows servers and workstations, particularly those managing SCADA systems, PLCs, engineering workstations, and critical infrastructure platforms running on Windows. Any organization using Windows 10, Windows 11, or Windows Server (2016, 2019, 2022, or 2025) for remote administration or process control is potentially at risk.
How it could be exploited
An attacker sends a malicious Remote Desktop Protocol (RDP) message over the network to a target system running a vulnerable version of Remote Desktop Client. The use-after-free vulnerability in the client processing logic allows the attacker's code to execute with the privileges of the user running the RDP client. No user interaction is strictly required beyond the victim being connected or accepting the connection attempt.
Prerequisites
  • Network access to the target system on port 3389 (RDP port) or any configured RDP alternative port
  • Target system must be running a vulnerable version of Windows with Remote Desktop Client enabled
  • For some attack scenarios, victim may need to initiate an RDP connection to an attacker-controlled server
remotely exploitableno authentication requiredlow complexityhigh CVSS score (8.8)exploitation more likely per vendor assessment
Exploitability
Some exploitation risk — EPSS score 1.3%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.8880
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.8880
Windows Server 2019All versionsBuild 10.0.17763.8880
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.8880
Windows Server 2022All versionsBuild 10.0.20348.5256
Remediation & Mitigation
0/3
Do now
0/1
WORKAROUNDIf immediate patching is not possible, disable Remote Desktop Services (RDP) on systems that do not require remote access, or restrict RDP access to specific trusted networks and IP addresses using Windows Firewall
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

Windows Server 2016
HOTFIXApply the June 2026 Windows security update to all systems running Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025
Long-term hardening
0/1
HARDENINGImplement network segmentation to isolate RDP traffic and limit which systems can initiate Remote Desktop connections to critical infrastructure servers
API: /api/v1/advisories/d2b39c93-e266-49fe-94a1-4a87d6556ad5

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Remote Desktop Client Remote Code Execution Vulnerability | CVSS 8.8 - OTPulse