Remote Desktop Client Remote Code Execution Vulnerability

Plan PatchCVSS 7.5CVE-2026-42993Jun 9, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionRequired
Summary

A heap-based buffer overflow vulnerability exists in the Remote Desktop Client that allows an attacker to execute arbitrary code on a system over a network. The vulnerability requires user interaction and moderate attack complexity, but successful exploitation grants full code execution with high impact on confidentiality, integrity, and availability.

What this means
What could happen
An attacker could execute arbitrary code on your Windows servers or workstations by sending a specially crafted Remote Desktop request, potentially gaining control of those systems and any connected networks or processes they manage.
Who's at risk
This affects organizations using Windows 10, Windows 11, Windows Server 2022, or Windows Server 2025 systems that have Remote Desktop enabled or accessible from networks. Water utilities, electric utilities, and other critical infrastructure using Windows-based engineering workstations, HMI systems, or server infrastructure are at risk if those systems accept RDP connections.
How it could be exploited
An attacker sends a malicious Remote Desktop Protocol (RDP) connection request containing a specially crafted payload that triggers the heap buffer overflow in the Remote Desktop Client. When a user accepts or connects to the RDP session, the overflow executes code with the privileges of the logged-in user.
Prerequisites
  • Network access to Remote Desktop Protocol port (typically 3389)
  • User must interact with or accept an RDP connection from the attacker
  • Vulnerable version of Windows with Remote Desktop Client running
remotely exploitableuser interaction requiredmoderate complexityheap buffer overflow enables code executionaffects Windows systems widely deployed in OT environments
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (18)
18 with fix
ProductAffected VersionsFix Status
Windows Server 2022All versionsBuild 10.0.20348.5256
Windows Server 2022 (Server Core installation)All versionsBuild 10.0.20348.5256
Windows 10 Version 21H2 for 32-bit SystemsAll versionsBuild 10.0.19044.7417
Windows 10 Version 21H2 for ARM64-based SystemsAll versionsBuild 10.0.19044.7417
Windows 10 Version 21H2 for x64-based SystemsAll versionsBuild 10.0.19044.7417
Remediation & Mitigation
0/5
Do now
0/3
WORKAROUNDRestrict network access to Remote Desktop Protocol port 3389 using firewall rules to only authorized management networks and workstations
HARDENINGDisable Remote Desktop on systems that do not require remote access
HARDENINGImplement Network Level Authentication (NLA) on all RDP-enabled systems to require credentials before full RDP session establishment
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

Windows Server 2022
HOTFIXApply the June 2026 Windows security update to all affected Windows 10, Windows 11, Windows Server 2022, and Windows Server 2025 systems
Long-term hardening
0/1
HARDENINGUse VPN or jump-box architecture to provide remote access instead of direct RDP exposure to untrusted networks
API: /api/v1/advisories/2bb06f20-dad8-406e-b9e6-cb9ae035d56a

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Remote Desktop Client Remote Code Execution Vulnerability | CVSS 7.5 - OTPulse