Remote Desktop Client Remote Code Execution Vulnerability

Plan PatchCVSS 8.8CVE-2026-58594Jul 14, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary

An integer overflow or wraparound vulnerability in Windows Remote Desktop Protocol (RDP) allows an unauthenticated attacker to execute arbitrary code over a network. The vulnerability affects all supported versions of Windows 10, Windows 11, and Windows Server from 2016 to 2025. Exploitation requires network access to port 3389 and user interaction (the victim must accept or respond to an incoming RDP connection).

What this means
What could happen
An attacker could execute arbitrary code on any Windows system running the Remote Desktop Protocol (RDP), potentially gaining full control of the device and any operational process it runs.
Who's at risk
All organizations running Windows 10, Windows 11, or Windows Server 2016–2025 are affected. This is particularly critical for utilities and infrastructure operators who may use RDP to access control systems, SCADA gateways, or engineering workstations remotely. Affected equipment includes domain controllers, server infrastructure, and any workstation with RDP enabled.
How it could be exploited
An attacker sends a specially crafted RDP connection request over the network to port 3389. The integer overflow in the RDP handler causes code execution. User interaction is required (the user must receive and respond to the connection), but the attacker can achieve this through social engineering or by chaining it with another vulnerability.
Prerequisites
  • Network access to port 3389 (RDP port)
  • User must accept or respond to an incoming RDP connection request
  • Target system must be running one of the affected Windows versions
remotely exploitablelow complexityuser interaction required (reduces but does not eliminate risk)high CVSS score (8.8)affects critical infrastructure if RDP is used for OT access
Exploitability
Unlikely to be exploited — EPSS score 0.8%
Affected products (23)
23 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9020
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9020
Windows Server 2019All versionsBuild 10.0.17763.9020
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9020
Windows Server 2022All versionsBuild 10.0.20348.5386
Remediation & Mitigation
0/4
Do now
0/2
WORKAROUNDRestrict RDP access (port 3389) at the firewall to only authorized administrative IP ranges or disable RDP entirely if not needed
HARDENINGDisable RDP on systems that do not require remote access
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

Windows Server 2016
HOTFIXApply the July 2026 Windows security update to all affected systems (Windows 10, Windows 11, Windows Server 2016, 2019, 2022, 2025)
Long-term hardening
0/1
HARDENINGEnforce multi-factor authentication for all RDP connections
API: /api/v1/advisories/81446e4b-6c4e-4082-b17a-8c1534b6bf3a

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.