Remote Desktop Client Remote Code Execution Vulnerability
Plan PatchCVSS 7.5CVE-2026-61363Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityHigh
User InteractionRequired
Summary
A heap-based buffer overflow in Windows Remote Desktop Client allows remote code execution when an attacker tricks a user into connecting to a malicious RDP server. The vulnerability affects Windows 10, Windows 11, and Windows Server 2016 through 2025. Exploitation requires user action (initiating the RDP connection) but no valid credentials to the attacker's server. Microsoft has released patches for all affected versions.
What this means
What could happen
A heap buffer overflow in the Remote Desktop Client allows an attacker who tricks a user into connecting to a malicious server to run arbitrary code on the user's workstation with the same privileges as the logged-in user. On OT workstations, this could lead to unauthorized access to engineering tools or configuration systems connected to industrial control systems.
Who's at risk
This affects Windows 10 and Windows 11 workstations and Windows Server 2016–2025 systems used as RDP servers or clients. Organizations operating HMI (Human Machine Interface) systems, engineering workstations running ICS configuration tools, or centralized remote access infrastructure for OT staff should prioritize updates for systems that maintain connections to control system networks.
How it could be exploited
An attacker sets up a malicious Remote Desktop (RDP) server. When a user initiates an RDP connection to the attacker's server, the vulnerability in the client is triggered during the connection handshake, allowing arbitrary code execution on the user's local machine. The attack requires user interaction (initiating the RDP connection) but no authentication to the attacker's server.
Prerequisites
- User must manually initiate an RDP connection to an attacker-controlled server
- No valid credentials required for the target RDP server
- User must be running vulnerable Windows version
remotely exploitableuser interaction requiredaffects engineering workstationslow EPSS score but wide platform footprint
Exploitability
Unlikely to be exploited — EPSS score 0.6%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/4
Do now
0/1WORKAROUNDRestrict RDP access to trusted internal networks only using firewall rules
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
HOTFIXApply the August 2026 Microsoft security update to all Windows systems
HARDENINGDisable RDP (port 3389) on systems that do not require remote access
Long-term hardening
0/1HARDENINGImplement network segmentation to isolate engineering workstations from internet-facing networks
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/c63bb497-b8cb-4d59-a19d-f32d668f5810Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.