Junglewise Threat Intelligence

CVE-2026-42909: Microsoft Remote Desktop Client heap overflow

CVE-2026-42909 · Severity: high · CVSS 7.5 · Published 2026-06-09

Technologies: Microsoft Remote Desktop Client. Vendors: Microsoft.

Executive brief

A vulnerability in the Microsoft Remote Desktop Client could allow an attacker to take control of a user's computer. This occurs when a user connects to a malicious server or is redirected to a compromised machine. If exploited, an attacker could gain the same permissions as the user, potentially leading to data theft or the installation of malicious software.

Technical details

A heap-based buffer overflow exists in the Microsoft Remote Desktop Client, likely stemming from improper synchronization or use-after-free conditions (CWE-362, CWE-416). The vulnerability is reachable over the network but requires a high level of attack complexity and user interaction, typically involving a user connecting to a malicious RDP server. Successful exploitation allows for remote code execution (RCE) in the context of the logged-on user. Microsoft has released information regarding this vulnerability via their Security Update Guide.

Affected products

  • Microsoft Remote Desktop Client

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats