Windows Remote Desktop Client Elevation of Privilege Vulnerability
Plan PatchCVSS 7.5CVE-2026-50330Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
A heap-based buffer overflow in the Windows Remote Desktop Client allows an unauthenticated attacker on the network to elevate privileges. The vulnerability affects Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 across multiple versions and architectures. Microsoft has released patches for all affected versions in the July 2026 security update. Exploitation is assessed as unlikely in the wild.
What this means
What could happen
An attacker on your network could exploit a buffer overflow in the Remote Desktop Client to gain elevated privileges on any Windows system where this component is present, potentially gaining administrative control.
Who's at risk
IT administrators and OT staff operating Windows 10 and Windows Server systems (2016, 2019, 2022, 2025) with Remote Desktop Client enabled. This affects any facility using Windows-based HMIs, engineering workstations, or SCADA client systems that rely on remote administration capabilities.
How it could be exploited
An attacker with network access sends a specially crafted RDP connection or message to a vulnerable Remote Desktop Client, triggering a heap buffer overflow. If successful, this allows the attacker to execute code with elevated privileges, potentially bypassing normal security restrictions and gaining administrative access to the affected system.
Prerequisites
- Network access to the Remote Desktop Client (typically port 3389 or via RDP traffic)
- Target system must be running a vulnerable version of Windows with Remote Desktop Client enabled
Remotely exploitableNo authentication requiredLow complexity attackAffects systems with elevated privileges
Exploitability
Some exploitation risk — EPSS score 1.3%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/3
Do now
0/1WORKAROUNDRestrict inbound RDP access to only authorized networks and systems using firewall rules
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
HOTFIXApply the July 2026 Microsoft security update to your Windows systems to patch CVE-2026-50330
HARDENINGDisable Remote Desktop services on systems that do not require remote access
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/0800be37-7682-4395-94ae-913f335d52fbGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.