Remote Desktop Client Remote Code Execution Vulnerability
Plan PatchCVSS 7.5CVE-2026-44801Jun 9, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionRequired
Summary
A use-after-free vulnerability in Remote Desktop Client allows an attacker to execute code on a system if a user opens a malicious RDP file. The vulnerability affects Windows 10 (all versions from 1607 to 22H2), Windows 11 (all versions), and Windows Server (2016, 2019, 2022, and 2025). Exploitation requires user interaction to open a malicious RDP file but does not require authentication or special privileges.
What this means
What could happen
An attacker could execute code on a Windows machine running Remote Desktop Client if a user is tricked into opening a malicious RDP file, potentially allowing the attacker to take control of the system or access sensitive data.
Who's at risk
IT and OT personnel using Windows workstations or servers running Remote Desktop Client, including system administrators, engineers, and helpdesk staff who may interact with RDP files. Windows 10 and Windows 11 workstations, Windows Server 2016, 2019, 2022, and 2025 systems are affected across all architectures.
How it could be exploited
An attacker would craft a malicious Remote Desktop (.rdp) file and trick a user into opening it through social engineering. When the file is opened in Remote Desktop Client, the use-after-free vulnerability is triggered, allowing the attacker to run arbitrary code with the privileges of the user who opened the file.
Prerequisites
- User interaction required: victim must open a malicious RDP file
- Remote Desktop Client must be installed on the system
remotely exploitablelow complexityuser interaction required
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1HARDENINGEducate users to avoid opening RDP files from untrusted or unexpected sources, especially those received via email or messaging
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
Windows Server 2019
HOTFIXUpdate Windows systems to the latest version available for your OS: Windows 10 Version 1809 to Build 10.0.17763.8880 or later, Windows 10 Version 21H2/22H2 to Build 10.0.19044.7417 or later, Windows 11 all versions to their respective latest builds listed, Windows Server 2019 to Build 10.0.17763.8880 or later, Windows Server 2022 to Build 10.0.20348.5256 or later, or Windows Server 2025 to Build 10.0.26100.32995 or later
Long-term hardening
0/1HARDENINGIf Remote Desktop Client is not required on user workstations, consider uninstalling or disabling the application
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/5df03a91-0689-4e2a-a58e-0135274dcb5eGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.