Junglewise Threat Intelligence

CVE-2026-47653: Microsoft Remote Desktop Client heap overflow

CVE-2026-47653 · Severity: high · CVSS 8.8 · Published 2026-06-09

Technologies: Microsoft Remote Desktop Client. Vendors: Microsoft.

Executive brief

A vulnerability in the Microsoft Remote Desktop Client allows an attacker to execute malicious code on a user's computer. This occurs when a user connects to a compromised or malicious server, potentially leading to a full system takeover and theft of sensitive data. The issue poses a significant risk to employees who use remote desktop tools to access corporate resources or support systems.

Technical details

A heap-based buffer overflow exists in the Microsoft Remote Desktop Client. The vulnerability is triggered when a user connects to a malicious RDP server, which sends specially crafted responses that exceed allocated memory buffers. While the NVD description notes a heap overflow, the Microsoft CWE classification also mentions Use After Free (CWE-416) characteristics. An attacker can exploit this to achieve remote code execution (RCE) in the context of the logged-in user. User interaction is required as the victim must initiate a connection to the attacker-controlled server.

Affected products

  • Microsoft Remote Desktop Client

Timeline

  • 2026-06-09: disclosed
  • 2026-06-09: advisory: Published by Microsoft and NVD

References

Related threats