Executive brief
A security vulnerability exists in Windows Remote Desktop, a tool used to access and control computers remotely. An attacker who already has a basic user account on the system could exploit this flaw to gain full administrative control. This could allow them to access sensitive data, install malicious software, or disrupt business operations on the affected machine.
Technical details
A heap-based buffer overflow (CWE-122) exists within the Windows Remote Desktop component. The vulnerability is triggered when the application improperly handles data in memory, leading to memory corruption. An attacker with low-privileged local access can exploit this flaw without any user interaction to execute code with elevated system privileges. This allows for a complete compromise of confidentiality, integrity, and availability on the local host. Microsoft has released security updates to address this issue via the MSRC update guide.
Affected products
- Microsoft Windows Remote Desktop
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory