Remote Desktop Client Remote Code Execution Vulnerability

Plan PatchCVSS 7.5CVE-2026-59134Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionRequired
Summary

A heap-based buffer overflow in the Remote Desktop Client allows an unauthorized attacker to execute arbitrary code on affected Windows systems over the network. The vulnerability exists in Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), and Windows Server 2016, 2019, 2022, and 2025 (both standard and Server Core installations, 32-bit, x64, and ARM64 architectures).

What this means
What could happen
A remote attacker could execute arbitrary code on any Windows workstation or server running the affected Remote Desktop Client, allowing unauthorized control of engineering workstations, SCADA servers, or other critical IT infrastructure supporting OT operations.
Who's at risk
Windows administrators responsible for engineering workstations, SCADA servers, HMI systems, and other critical IT infrastructure used to manage water treatment, wastewater systems, electrical distribution, or other industrial processes. This affects Windows 10 (versions 1607, 1809, 21H2, 22H2), Windows 11 (versions 23H2, 24H2, 25H2, 26H1), Windows Server 2016, 2019, 2022, and 2025 on both 32-bit and 64-bit systems.
How it could be exploited
An attacker sends a specially crafted Remote Desktop Protocol (RDP) packet to a Windows system running a vulnerable version of Remote Desktop Client. The packet triggers a heap buffer overflow, allowing the attacker to execute code with the privileges of the user running the client. No user authentication is required if the attacker can reach the RDP port (3389/TCP by default).
Prerequisites
  • Network access to RDP port 3389 (TCP) on affected Windows system
  • Vulnerable version of Remote Desktop Client installed and running
  • User interaction not required for exploitation
Remotely exploitable without authenticationAffects critical infrastructure IT systemsHeap-based buffer overflow (moderate complexity exploitation)No user interaction required
Exploitability
Unlikely to be exploited — EPSS score 0.6%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9115
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9115
Windows Server 2019All versionsBuild 10.0.17763.9115
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9115
Windows Server 2022All versionsBuild 10.0.20348.5499
Remediation & Mitigation
0/8
Do now
0/1
WORKAROUNDRestrict inbound RDP access (port 3389/TCP) to only authorized engineering workstations and jump servers using firewall rules; block RDP from untrusted networks immediately
Schedule — requires maintenance window
0/6

Patching may require device reboot — plan for process interruption

Windows Server 2019
HOTFIXUpdate Windows Server 2019 systems to Build 10.0.17763.9115 or later
Windows Server 2022
HOTFIXUpdate Windows Server 2022 systems to Build 10.0.20348.5499 or later
Windows Server 2025
HOTFIXUpdate Windows Server 2025 systems to Build 10.0.26100.33296 or later
All products
HOTFIXUpdate Windows 10 Version 1809 systems to Build 10.0.17763.9115 or later
HOTFIXUpdate Windows 10 Version 21H2 and 22H2 systems to the latest August 2026 security update
HOTFIXUpdate Windows 11 systems to the latest August 2026 security update
Long-term hardening
0/1
HARDENINGSegment engineering workstations and SCADA servers on a separate network with restricted RDP access from office networks
API: /api/v1/advisories/a5a398f1-3f94-41c1-8c21-1d6360e9510e

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Remote Desktop Client Remote Code Execution Vulnerability | CVSS 7.5 - OTPulse