Remote Desktop Client Remote Code Execution Vulnerability

Plan PatchCVSS 9.8CVE-2026-54990Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary

A heap-based buffer overflow vulnerability exists in the Remote Desktop Client component of Windows Server 2025 and Windows 11 (versions 24H2, 25H2, and 26H1). An unauthenticated attacker on the network can trigger this overflow by sending a specially crafted packet to the RDP service, leading to arbitrary code execution with the privileges of the affected user. The vulnerability requires only network access to the Remote Desktop service and no user interaction.

What this means
What could happen
An attacker could send a specially crafted network packet to a Windows machine running Remote Desktop Client, causing a heap buffer overflow that allows arbitrary code execution with the privileges of the user running the client.
Who's at risk
Affects Windows Server 2025 and Windows 11 systems (versions 24H2, 25H2, and 26H1) running Remote Desktop Client. This impacts any organization using these Windows versions for remote access to industrial or critical infrastructure management systems, SCADA workstations, or engineering terminals.
How it could be exploited
An attacker on the network sends a malicious packet to the Remote Desktop Client service on a target Windows machine. The packet triggers a heap buffer overflow in the RDP protocol handler, allowing the attacker to execute arbitrary commands on the system without authentication.
Prerequisites
  • Network access to Remote Desktop Client service (typically port 3389)
  • Target machine must be running one of the affected Windows versions
  • No user authentication required
remotely exploitableno authentication requiredlow complexityaffects operator workstations and engineering systems
Exploitability
Unlikely to be exploited — EPSS score 0.8%
Affected products (8)
8 with fix
ProductAffected VersionsFix Status
Windows Server 2025 (Server Core installation)All versionsBuild 10.0.26100.33158
Windows 11 Version 25H2 for ARM64-based SystemsAll versionsBuild 10.0.26200.8875
Windows 11 Version 25H2 for x64-based SystemsAll versionsBuild 10.0.26200.8875
Windows 11 Version 24H2 for ARM64-based SystemsAll versionsBuild 10.0.26100.8875
Windows 11 Version 24H2 for x64-based SystemsAll versionsBuild 10.0.26100.8875
Windows Server 2025All versionsBuild 10.0.26100.33158
Windows 11 version 26H1 for x64-based SystemsAll versionsBuild 10.0.28000.2269
Windows 11 Version 26H1 for ARM64-based SystemsAll versionsBuild 10.0.28000.2525
Remediation & Mitigation
0/6
Do now
0/2
HARDENINGRestrict network access to Remote Desktop services (port 3389) to only authorized administrative workstations and jump hosts
WORKAROUNDDisable Remote Desktop Client if not required for operations
Schedule — requires maintenance window
0/4

Patching may require device reboot — plan for process interruption

Windows Server 2025
HOTFIXApply the July 2026 security update to Windows Server 2025 (Build 10.0.26100.33158 or later)
All products
HOTFIXApply the July 2026 security update to Windows 11 24H2 systems (Build 10.0.26100.8875 or later)
HOTFIXApply the July 2026 security update to Windows 11 25H2 systems (Build 10.0.26200.8875 or later)
HOTFIXApply the July 2026 security update to Windows 11 26H1 systems (Build 10.0.28000.2269 or later for x64, Build 10.0.28000.2525 or later for ARM64)
API: /api/v1/advisories/59fd938f-c3e2-486e-af44-ef469206b55c

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.