Remote Desktop Client Remote Code Execution Vulnerability

Plan PatchCVSS 7.1CVE-2026-69358Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityHigh
User InteractionRequired
Summary

Uninitialized resource in Remote Desktop Client allows an authorized attacker to execute code over a network. An attacker with valid credentials could exploit this flaw by initiating a malicious remote desktop connection, leading to code execution on the client system.

What this means
What could happen
An attacker with valid credentials could execute arbitrary code on engineering workstations or operator desks that use Remote Desktop, potentially compromising SCADA clients or control system access points.
Who's at risk
OT operators and engineers using Remote Desktop to access control systems, engineering workstations, HMI interfaces, and operator stations running Windows 10 or Windows Server 2016–2025. This includes any staff connecting to PLCs, distributed control systems, or historian servers via Remote Desktop.
How it could be exploited
An attacker with valid network credentials establishes a remote desktop connection to a target system running a vulnerable Remote Desktop Client. During the connection handshake, the attacker supplies a specially crafted payload that exploits the uninitialized resource, causing code execution on the client side with the privileges of the logged-in user.
Prerequisites
  • Valid network credentials for the target system
  • Network access to the Remote Desktop port (typically 3389)
  • Remote Desktop Client running on a vulnerable Windows version
  • User must be actively using or attempting to use Remote Desktop
Requires valid credentialsHigh CVSS score (7.1)Affects multiple Windows versions widely deployed in OT environments
Exploitability
Unlikely to be exploited — EPSS score 0.5%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Remediation & Mitigation
0/5
Do now
0/2
WORKAROUNDRestrict Remote Desktop access to authorized engineering networks only using firewall rules on port 3389
HARDENINGDisable Remote Desktop on systems that do not require it, particularly operator stations and engineering workstations not actively used for remote access
Schedule — requires maintenance window
0/1

Patching may require device reboot — plan for process interruption

HOTFIXApply Microsoft September 2026 security update to all Windows 10, Windows 11, and Windows Server systems
Long-term hardening
0/2
HARDENINGImplement network segmentation to isolate control system access points from general IT networks
HARDENINGEnforce multi-factor authentication for all Remote Desktop connections to control system and engineering workstations
API: /api/v1/advisories/24be3b4c-9833-43ff-baa5-9be91fd7cc43

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.