Remote Desktop Client Remote Code Execution Vulnerability

Plan PatchCVSS 8.8CVE-2026-69485Sep 8, 2026
Microsoft
IT in OT - Windows Server and Active Directory are widely deployed in OT environments
Attack path
Attack VectorNetwork
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary

A vulnerability in the Remote Desktop Client uses uninitialized resources, allowing an authenticated attacker to execute arbitrary code over a network. The flaw affects Windows 10 (versions 1607, 1809, 21H2, 22H2) and Windows 11 (versions 23H2, 24H2, 25H2, 26H1), as well as Windows Server 2016, 2019, 2022, and 2025. Exploitation requires valid Remote Desktop credentials and network access to the RDP port. Microsoft has released patches for all affected versions.

What this means
What could happen
An attacker with valid credentials can run arbitrary code on a Windows system via Remote Desktop Client, potentially allowing them to modify critical configurations, access sensitive data, or disrupt plant operations on systems using Remote Desktop for remote management.
Who's at risk
Windows 10 and Windows Server administrators who use Remote Desktop for remote system management, including IT staff managing SCADA workstations, HMI servers, and other operational technology infrastructure running Windows. Organizations operating water, power, or other critical infrastructure using Windows-based remote management tools are affected.
How it could be exploited
An attacker with valid logon credentials initiates a Remote Desktop connection to a target Windows system. During the connection handshake, the attacker sends specially crafted data that exploits uninitialized memory in the Remote Desktop Client component, causing arbitrary code execution with the privileges of the connected user. The attacker can then execute commands to compromise the system.
Prerequisites
  • Valid user credentials for Remote Desktop access (local or domain account)
  • Network access to Remote Desktop Protocol (RDP) port 3389 or configured RDP listening port
  • Remote Desktop enabled and listening on the target Windows system
Remotely exploitableRequires valid credentialsAffects systems used for OT remote management
Exploitability
Unlikely to be exploited — EPSS score 0.9%
Affected products (26)
26 with fix
ProductAffected VersionsFix Status
Windows 10 Version 1809 for 32-bit SystemsAll versionsBuild 10.0.17763.9245
Windows 10 Version 1809 for x64-based SystemsAll versionsBuild 10.0.17763.9245
Windows Server 2019All versionsBuild 10.0.17763.9245
Windows Server 2019 (Server Core installation)All versionsBuild 10.0.17763.9245
Windows Server 2022All versionsBuild 10.0.20348.5622
Remediation & Mitigation
0/5
Do now
0/2
WORKAROUNDRestrict network access to Remote Desktop (RDP port 3389) using Windows Firewall or network firewall rules; allow only from known administrative networks
HARDENINGDisable Remote Desktop on systems that do not require remote access for operations or management
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

HOTFIXApply the September 2026 Windows security update to all affected Windows 10 and Windows Server systems
HARDENINGEnforce multi-factor authentication (MFA) for Remote Desktop logons to reduce the risk of credential compromise
Long-term hardening
0/1
HARDENINGImplement network segmentation to isolate systems running Remote Desktop from untrusted networks
API: /api/v1/advisories/6968e509-b575-4cb6-84b0-80d82e544fbc

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.