Remote Desktop Client Remote Code Execution Vulnerability
Plan PatchCVSS 7.5CVE-2026-42992Jun 9, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionRequired
Summary
Heap-based buffer overflow in Remote Desktop Client allows an attacker to execute code over a network. The vulnerability affects multiple Windows versions including Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025.
What this means
What could happen
An attacker could execute arbitrary code on your Windows computers, including HMI systems or engineering workstations connected to your network. This could allow them to compromise control system operations or steal sensitive industrial data.
Who's at risk
This affects IT staff and control system engineers who use Windows 10, Windows 11, or Windows Server systems to connect to industrial equipment via Remote Desktop Protocol. It is relevant for any utility or water authority using Windows-based HMI systems, engineering workstations, or remote access infrastructure for managing SCADA or PLC systems.
How it could be exploited
An attacker would send a specially crafted Remote Desktop Protocol (RDP) message to a Windows system running Remote Desktop Client. The message exploits a heap buffer overflow in the RDP parsing code to execute commands with the privileges of the user running RDP. User interaction (clicking or opening a connection) is required to trigger the vulnerability.
Prerequisites
- Network access to Remote Desktop Client or RDP port (typically 3389 on target systems)
- User interaction required to open RDP connection to a malicious or compromised server
remotely exploitablerequires user interactionlow complexityaffects engineering workstations used in OT environments
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/4
Do now
0/1WORKAROUNDRestrict network access to RDP ports (default port 3389) to only authorized administrative and engineering workstations using firewall rules
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXApply the 2026-Jun Windows security update to all affected systems (Windows 10, 11, Server 2016, 2019, 2022, 2025)
Long-term hardening
0/2HARDENINGSegment your control system network so that only approved workstations can reach devices using RDP
HARDENINGConfigure RDP to use Network Level Authentication (NLA) to require user authentication before connection is established
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/113a9f57-4e93-4ba5-8b59-a47c0b03b446Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.