Remote Desktop Protocol Remote Code Execution Vulnerability
Plan PatchCVSS 9.8CVE-2026-56190Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionNone needed
Summary
A use of uninitialized resource vulnerability in Windows Remote Desktop Protocol (RDP) allows an unauthenticated attacker to execute arbitrary code remotely. The vulnerability affects Windows 10 (all versions), Windows 11 (all versions), Windows Server 2016, 2019, 2022, and 2025. Successful exploitation requires only network access to the RDP port and no user credentials. Microsoft has released security updates for all affected versions with specific build numbers for each operating system version.
What this means
What could happen
An attacker with network access to the Remote Desktop Protocol (RDP) port could execute arbitrary code on the affected Windows system, potentially gaining control of engineering workstations, HMIs, or server infrastructure that manages OT operations.
Who's at risk
This affects any Windows 10, Windows 11, Windows Server 2016, 2019, 2022, and 2025 systems that have Remote Desktop Protocol enabled. This includes engineering workstations, HMI servers, historian servers, domain controllers, and other IT infrastructure that may communicate with or control OT devices. Water utilities and electric utilities should prioritize patching any Internet-facing RDP services and internal servers managing SCADA or control systems.
How it could be exploited
An attacker sends a specially crafted RDP connection request to port 3389 without authentication. The uninitialized resource in the RDP service allows the attacker to execute code in the system context, potentially taking full control of the machine.
Prerequisites
- Network access to RDP port 3389 (TCP)
- RDP service enabled on the target system
- No authentication required
Remotely exploitableNo authentication requiredLow complexityAffects all Windows versionsAffects both IT and OT-connected infrastructure
Exploitability
Unlikely to be exploited — EPSS score 1.0%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/12
Do now
0/2WORKAROUNDRestrict RDP access to authorized users and systems; disable RDP on machines that do not require remote administration
HARDENINGConfigure firewall rules to block inbound connections to RDP port 3389 from untrusted networks
Schedule — requires maintenance window
0/10Patching may require device reboot — plan for process interruption
Windows Server 2016
HOTFIXUpdate Windows Server 2016 systems to Build 10.0.14393.9339 or later
Windows Server 2019
HOTFIXUpdate Windows Server 2019 systems to Build 10.0.17763.9020 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 systems to Build 10.0.20348.5386 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 systems to Build 10.0.26100.33158 or later
All products
HOTFIXUpdate Windows 10 Version 1809 systems to Build 10.0.17763.9020 or later
HOTFIXUpdate Windows 10 Version 21H2 systems to Build 10.0.19044.7548 or later
HOTFIXUpdate Windows 10 Version 22H2 systems to Build 10.0.19045.7548 or later
HOTFIXUpdate Windows 11 Version 24H2 systems to Build 10.0.26100.8875 or later
HOTFIXUpdate Windows 11 Version 25H2 systems to Build 10.0.26200.8875 or later
HOTFIXUpdate Windows 11 version 26H1 systems to Build 10.0.28000.2269 or later (x64) or 10.0.28000.2525 or later (ARM64)
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/53e89bd1-9677-4121-8459-26ecd9359f4dGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.