Remote Desktop Client Remote Code Execution Vulnerability

Plan PatchCVSS 7.5CVE-2026-44799Jun 9, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionRequired
Summary

A heap-based buffer overflow vulnerability exists in the Remote Desktop Client that allows an attacker to execute arbitrary code if a user connects to a malicious RDP server. The vulnerability is triggered during the RDP connection handshake and requires no prior authentication. Exploitation is assessed as less likely but possible. Microsoft has released patches for all affected Windows versions.

What this means
What could happen
A heap buffer overflow in the Remote Desktop Client could allow an attacker to run arbitrary code on your desktop or server if you connect to a malicious RDP server. This could lead to unauthorized access, data theft, or disruption of operations on affected machines.
Who's at risk
Organizations running Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025 should prioritize patching any desktop computers or servers that use Remote Desktop Client for administrative access or staff remote work. This includes all 32-bit, x64, and ARM64 system architectures. Engineering workstations and SCADA/OT admin consoles that rely on RDP for remote monitoring or control are also at risk.
How it could be exploited
An attacker sets up a malicious Remote Desktop Protocol (RDP) server and tricks a user or automated process into connecting to it. When the victim's Remote Desktop Client connects, the overflow is triggered during the connection handshake, allowing the attacker to execute code on the victim's machine with the privileges of the user running the client.
Prerequisites
  • Network access to port 3389 or RDP client connecting to attacker-controlled server
  • User or automated process initiates RDP connection to the malicious server
  • Vulnerable version of Windows 10, Windows 11, Windows Server 2016, 2019, 2022, or 2025
remotely exploitableuser interaction required (user must initiate RDP connection)heap buffer overflow (moderate complexity)affects all recent Windows versionscommonly used in OT administrative access
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.8880
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.8880
Windows Server 2019All versionsBuild 10.0.17763.8880
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.8880
Windows Server 2022All versionsBuild 10.0.20348.5256
Remediation & Mitigation
0/9
Do now
0/1
WORKAROUNDRestrict RDP access to trusted networks and authorized users only; disable RDP on systems that do not require remote access
Schedule — requires maintenance window
0/7

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXUpdate Windows Server 2019 to Build 10.0.17763.8880 or later via Windows Update
Windows Server 2022
HOTFIXUpdate Windows Server 2022 to Build 10.0.20348.5256 or later via Windows Update
Windows Server 2025
HOTFIXUpdate Windows Server 2025 to Build 10.0.26100.32995 or later via Windows Update
All products
HOTFIXUpdate Windows 10 Version 1809 (32-bit) to Build 10.0.17763.8880 or later via Windows Update
HOTFIXUpdate Windows 10 Version 1809 (x64) to Build 10.0.17763.8880 or later via Windows Update
HOTFIXUpdate Windows 10 Version 21H2 and 22H2 to the latest available build via Windows Update
HOTFIXUpdate Windows 11 all versions to the latest available build via Windows Update
Long-term hardening
0/1
HARDENINGUse VPN or network segmentation to limit which machines can initiate RDP connections outside your organization
API: /api/v1/advisories/92503364-327b-458d-804f-30fb13163c3a

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Remote Desktop Client Remote Code Execution Vulnerability | CVSS 7.5 - OTPulse