Executive brief
A security vulnerability exists in the Microsoft Remote Desktop Client, a tool used by employees to connect to remote computers and servers. An attacker could exploit this flaw to take control of a user's computer if the user is tricked into connecting to a malicious server. This could lead to the theft of sensitive data, installation of malware, or a complete compromise of the affected workstation.
Technical details
A heap-based buffer overflow (CWE-122) exists in the Microsoft Remote Desktop Client. The vulnerability is triggered when the client processes specially crafted data from a malicious Remote Desktop server. While the attack vector is network-based and requires no prior privileges, it carries a high complexity (AC:H) and requires user interaction (UI:R), typically involving the user initiating a connection to a compromised or attacker-controlled RDP host. Successful exploitation allows for remote code execution (RCE) in the context of the logged-on user. Microsoft has released information regarding this vulnerability via their Security Update Guide.
Affected products
- Microsoft Remote Desktop Client
Timeline
- 2026-06-09: disclosed: Initial publication by Microsoft and NVD.
- 2026-06-09: advisory