Remote Desktop Client Remote Code Execution Vulnerability
Plan PatchCVSS 8.8CVE-2026-62824Aug 11, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary
Stack-based buffer overflow in Remote Desktop Client allows an attacker to execute code over a network. Affected products include Windows 10 Version 1607 (32-bit and x64) and Windows Server 2016 (including Server Core). The vulnerability requires user interaction via a malicious RDP connection.
What this means
What could happen
An attacker who tricks a user into connecting to a malicious Remote Desktop server could execute code on the victim's machine with the user's privileges, potentially gaining control of engineering workstations or server systems.
Who's at risk
Organizations running Windows 10 Version 1607 or Windows Server 2016 systems—particularly those where engineering workstations or servers use Remote Desktop for access. This affects utilities managing SCADA systems or PLCs via RDP-enabled jump hosts or remote engineering stations.
How it could be exploited
An attacker sets up a malicious RDP server and tricks a user into connecting to it (via social engineering or by compromising a legitimate RDP service). When the Remote Desktop Client connects, the buffer overflow is triggered, allowing arbitrary code execution on the client machine with the connecting user's privileges.
Prerequisites
- Network access to reach the victim's RDP client (attacker's malicious RDP server must be reachable)
- User interaction required—victim must initiate an RDP connection to the attacker's server or a compromised RDP endpoint
- Victim running Windows 10 Version 1607 or Windows Server 2016 with unpatched Remote Desktop Client
remotely exploitablerequires user interactionlow complexity attackstack-based buffer overflow
Exploitability
Unlikely to be exploited — EPSS score 0.6%
Affected products (4)
4 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/4
Do now
0/1WORKAROUNDEducate users not to connect to untrusted or unexpected RDP endpoints
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
Windows Server 2016
HOTFIXApply the 2026-Aug security update to Windows 10 Version 1607 and Windows Server 2016 systems
Long-term hardening
0/2HARDENINGRestrict outbound RDP connections from engineering workstations and critical servers to only approved RDP servers using firewall rules
HARDENINGDisable RDP on systems that do not require remote access, or restrict it to a secure jump host architecture
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/90f56a37-1673-4b8f-bf64-91537e70d164Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.