Remote Desktop Client Remote Code Execution Vulnerability

Plan PatchCVSS 8.8CVE-2026-62824Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary

Stack-based buffer overflow in Remote Desktop Client allows an attacker to execute code over a network. Affected products include Windows 10 Version 1607 (32-bit and x64) and Windows Server 2016 (including Server Core). The vulnerability requires user interaction via a malicious RDP connection.

What this means
What could happen
An attacker who tricks a user into connecting to a malicious Remote Desktop server could execute code on the victim's machine with the user's privileges, potentially gaining control of engineering workstations or server systems.
Who's at risk
Organizations running Windows 10 Version 1607 or Windows Server 2016 systems—particularly those where engineering workstations or servers use Remote Desktop for access. This affects utilities managing SCADA systems or PLCs via RDP-enabled jump hosts or remote engineering stations.
How it could be exploited
An attacker sets up a malicious RDP server and tricks a user into connecting to it (via social engineering or by compromising a legitimate RDP service). When the Remote Desktop Client connects, the buffer overflow is triggered, allowing arbitrary code execution on the client machine with the connecting user's privileges.
Prerequisites
  • Network access to reach the victim's RDP client (attacker's malicious RDP server must be reachable)
  • User interaction required—victim must initiate an RDP connection to the attacker's server or a compromised RDP endpoint
  • Victim running Windows 10 Version 1607 or Windows Server 2016 with unpatched Remote Desktop Client
remotely exploitablerequires user interactionlow complexity attackstack-based buffer overflow
Exploitability
Unlikely to be exploited — EPSS score 0.6%
Affected products (4)
4 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1607 for 32-bit SystemsAll versionsBuild 10.0.14393.9418
Windows 10 Version 1607 for x64-based SystemsAll versionsBuild 10.0.14393.9418
Windows Server 2016All versionsBuild 10.0.14393.9418
Windows Server 2016 (Server Core installation)All versionsBuild 10.0.14393.9418
Remediation & Mitigation
0/4
Do now
0/1
WORKAROUNDEducate users not to connect to untrusted or unexpected RDP endpoints
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

Windows Server 2016
HOTFIXApply the 2026-Aug security update to Windows 10 Version 1607 and Windows Server 2016 systems
Long-term hardening
0/2
HARDENINGRestrict outbound RDP connections from engineering workstations and critical servers to only approved RDP servers using firewall rules
HARDENINGDisable RDP on systems that do not require remote access, or restrict it to a secure jump host architecture
API: /api/v1/advisories/90f56a37-1673-4b8f-bf64-91537e70d164

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Remote Desktop Client Remote Code Execution Vulnerability | CVSS 8.8 - OTPulse