Remote Desktop Client Remote Code Execution Vulnerability

Plan PatchCVSS 7.5CVE-2026-61352Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionRequired
Summary

A race condition in Windows Remote Desktop Client allows an unauthorized attacker to execute arbitrary code over the network. The vulnerability exists in the shared resource synchronization mechanism. Exploitation requires a user to initiate a Remote Desktop Client connection, at which point an attacker can send a specially crafted RDP message to execute code with the user's privileges. Affected systems include Windows 10 (all recent versions), Windows 11 (all versions), Windows Server 2016, 2019, 2022, and 2025. Microsoft has released fixes for all affected products in the August 2026 security update.

What this means
What could happen
An attacker could run arbitrary code on a Windows computer or server running Remote Desktop Client, potentially gaining full control and the ability to manipulate connected systems or steal sensitive data.
Who's at risk
This affects IT administrators and operators who use Windows computers or servers (Windows 10, Windows 11, Windows Server 2016, 2019, 2022, 2025) with Remote Desktop Client enabled for remote system management. Water utilities and electric utilities should be concerned if they use Windows-based HMI workstations, engineering computers, or centralized IT infrastructure that relies on RDP for remote access to control systems or business networks.
How it could be exploited
An attacker sends a specially crafted Remote Desktop Protocol (RDP) message to a Windows system. When a user connects using Remote Desktop Client, the race condition in the shared resource handling allows the attacker's code to execute with the privileges of the connected user. The attack requires user interaction (a user must initiate an RDP connection), but occurs over the network without requiring credentials.
Prerequisites
  • Network access to RDP port 3389 or other RDP endpoint
  • User must initiate a Remote Desktop Client connection to an attacker-controlled or compromised RDP server
  • No valid credentials required
Remotely exploitableLow complexityUser interaction required (connection initiation)Affects multiple Windows OS versionsNo authentication required
Exploitability
Unlikely to be exploited — EPSS score 0.4%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9115
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9115
Windows Server 2019All versionsBuild 10.0.17763.9115
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9115
Windows Server 2022All versionsBuild 10.0.20348.5499
Remediation & Mitigation
0/4
Do now
0/2
WORKAROUNDRestrict RDP access (port 3389) at the firewall to only authorized administrative workstations or jump hosts
WORKAROUNDDisable Remote Desktop services on systems that do not require remote administrative access
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply the August 2026 Windows security update to all Windows 10, Windows 11, and Windows Server systems listed in the affected products
Long-term hardening
0/1
HARDENINGImplement network segmentation to isolate engineering workstations and SCADA servers from systems that receive inbound RDP connections
API: /api/v1/advisories/95bfbc8c-01d1-49f0-abb4-8b3506f4747e

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Remote Desktop Client Remote Code Execution Vulnerability | CVSS 7.5 - OTPulse