Remote Desktop Client Remote Code Execution Vulnerability

Plan PatchCVSS 7.5CVE-2026-42992Jun 9, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionRequired
Summary

Heap-based buffer overflow in Remote Desktop Client allows an attacker to execute code over a network. The vulnerability affects multiple Windows versions including Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025.

What this means
What could happen
An attacker could execute arbitrary code on your Windows computers, including HMI systems or engineering workstations connected to your network. This could allow them to compromise control system operations or steal sensitive industrial data.
Who's at risk
This affects IT staff and control system engineers who use Windows 10, Windows 11, or Windows Server systems to connect to industrial equipment via Remote Desktop Protocol. It is relevant for any utility or water authority using Windows-based HMI systems, engineering workstations, or remote access infrastructure for managing SCADA or PLC systems.
How it could be exploited
An attacker would send a specially crafted Remote Desktop Protocol (RDP) message to a Windows system running Remote Desktop Client. The message exploits a heap buffer overflow in the RDP parsing code to execute commands with the privileges of the user running RDP. User interaction (clicking or opening a connection) is required to trigger the vulnerability.
Prerequisites
  • Network access to Remote Desktop Client or RDP port (typically 3389 on target systems)
  • User interaction required to open RDP connection to a malicious or compromised server
remotely exploitablerequires user interactionlow complexityaffects engineering workstations used in OT environments
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.8880
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.8880
Windows Server 2019All versionsBuild 10.0.17763.8880
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.8880
Windows Server 2022All versionsBuild 10.0.20348.5256
Remediation & Mitigation
0/4
Do now
0/1
WORKAROUNDRestrict network access to RDP ports (default port 3389) to only authorized administrative and engineering workstations using firewall rules
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the 2026-Jun Windows security update to all affected systems (Windows 10, 11, Server 2016, 2019, 2022, 2025)
Long-term hardening
0/2
HARDENINGSegment your control system network so that only approved workstations can reach devices using RDP
HARDENINGConfigure RDP to use Network Level Authentication (NLA) to require user authentication before connection is established
API: /api/v1/advisories/113a9f57-4e93-4ba5-8b59-a47c0b03b446

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Remote Desktop Client Remote Code Execution Vulnerability | CVSS 7.5 - OTPulse