Junglewise Threat Intelligence

CVE-2026-42913: Microsoft Remote Desktop Client heap overflow

CVE-2026-42913 · Severity: high · CVSS 7.5 · Published 2026-06-09

Technologies: Microsoft Remote Desktop Client. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Microsoft Remote Desktop Client, a tool used to connect to and control remote computers. An attacker could exploit this flaw to run malicious code on a user's computer if the user is tricked into connecting to a malicious server. This could lead to a total compromise of the user's system, including data theft and unauthorized access to corporate resources.

Technical details

A heap-based buffer overflow vulnerability exists in the Microsoft Remote Desktop Client. The flaw is triggered by improper synchronization (race condition) and use-after-free issues when processing malicious traffic from a Remote Desktop server. An unauthenticated attacker can exploit this by convincing a user to connect to a compromised or malicious RDP server. Successful exploitation allows for remote code execution (RCE) in the context of the logged-on user. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Remote Desktop Client

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats