Junglewise Threat Intelligence

CVE-2026-44801: Microsoft Remote Desktop Client heap overflow remote code execution

CVE-2026-44801 · Severity: high · CVSS 7.5 · Published 2026-06-09

Technologies: Microsoft Remote Desktop Client. Vendors: Microsoft.

Executive brief

A security vulnerability has been identified in the Microsoft Remote Desktop Client, a tool used by employees to access remote computers and servers. An attacker could exploit this flaw to gain control over a user's computer if the user is tricked into connecting to a malicious server. This could result in the theft of sensitive data, installation of malware, or a complete compromise of the affected workstation.

Technical details

A heap-based buffer overflow vulnerability exists in the Microsoft Remote Desktop Client. The flaw is triggered when the client processes specially crafted data sent from a malicious Remote Desktop server. While the attack vector is network-based and requires no prior privileges, it has high complexity as it requires a user to initiate a connection to a compromised or attacker-controlled server (User Interaction required). Successful exploitation allows for remote code execution (RCE) in the context of the logged-on user. Although the NVD description mentions a buffer overflow, the Microsoft-provided CWE-416 suggests a Use-After-Free condition may also be involved in the memory corruption.

Affected products

  • Microsoft Remote Desktop Client

Timeline

  • 2026-06-09: disclosed: Initial disclosure by Microsoft and NVD publication.

References

Related threats