Remote Desktop Client Remote Code Execution Vulnerability
A race condition in Windows Remote Desktop Client allows an unauthorized attacker to execute arbitrary code over the network. The vulnerability exists in the shared resource synchronization mechanism. Exploitation requires a user to initiate a Remote Desktop Client connection, at which point an attacker can send a specially crafted RDP message to execute code with the user's privileges. Affected systems include Windows 10 (all recent versions), Windows 11 (all versions), Windows Server 2016, 2019, 2022, and 2025. Microsoft has released fixes for all affected products in the August 2026 security update.
- Network access to RDP port 3389 or other RDP endpoint
- User must initiate a Remote Desktop Client connection to an attacker-controlled or compromised RDP server
- No valid credentials required
Patching may require device reboot — plan for process interruption
/api/v1/advisories/95bfbc8c-01d1-49f0-abb4-8b3506f4747eGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.