Remote Desktop Client Remote Code Execution Vulnerability

Plan PatchCVSS 8.8CVE-2026-50474Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary

A use-after-free vulnerability in the Remote Desktop Client allows an unauthorized attacker to execute code over the network. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server operating systems. Exploitation is assessed as unlikely at this time.

What this means
What could happen
An attacker could execute arbitrary code on a Windows system running Remote Desktop Client by sending a specially crafted network message, potentially gaining full control of the affected computer. This could impact any system relying on remote desktop connections for operations or administrative access.
Who's at risk
Windows system administrators and operators using Remote Desktop Client for administrative access or remote operations. Affects Windows 10 (all versions 1607–22H2), Windows 11 (all versions 24H2–26H1), Windows Server 2016, 2019, 2022, and 2025.
How it could be exploited
An attacker sends a malicious packet over the network to the Remote Desktop Client service. The vulnerability exists in how the client handles memory after freeing it, so a specially crafted message triggers the use-after-free condition, allowing code execution without requiring the user to do anything first.
Prerequisites
  • Network access to the affected Windows system on the Remote Desktop Protocol (RDP) port (typically 3389)
  • Victim system must be running affected Windows versions
remotely exploitablelow complexityno authentication required
Exploitability
Unlikely to be exploited — EPSS score 0.8%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/2
Do now
0/1
WORKAROUNDRestrict network access to RDP port 3389 using firewall rules, allowing connections only from trusted administrative workstations or networks
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the 2026-Jul (July 2026) security update for your Windows version
API: /api/v1/advisories/bbb2bdc4-355d-454d-b1fc-2758865752d8

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Remote Desktop Client Remote Code Execution Vulnerability | CVSS 8.8 - OTPulse