Junglewise Threat Intelligence

CVE-2026-47289: Microsoft Remote Desktop Client heap overflow

CVE-2026-47289 · Severity: high · CVSS 8.8 · Published 2026-06-09

Technologies: Microsoft Remote Desktop Client. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Microsoft Remote Desktop Client, a tool used by employees to access remote computers and servers. An attacker could exploit this flaw to gain full control over a user's computer if the user connects to a malicious server. This could lead to the theft of sensitive data, installation of malware, or complete disruption of the user's workstation.

Technical details

A heap-based buffer overflow vulnerability (CWE-122) exists in the Microsoft Remote Desktop Client. The flaw is triggered when the client processes specially crafted data sent from a malicious Remote Desktop server. While the attack vector is listed as network-based, it requires a level of user interaction where a user must connect to a compromised or attacker-controlled RDP server. Successful exploitation allows for remote code execution (RCE) in the context of the logged-on user, potentially leading to full system compromise. Microsoft has released information regarding this vulnerability via the MSRC Update Guide.

Affected products

  • Microsoft Remote Desktop Client

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory

References

Related threats