Executive brief
A vulnerability in the Microsoft Remote Desktop Client allows an attacker to execute malicious code on a user's computer. This occurs when a user connects to a compromised or malicious server, potentially leading to a full system takeover and theft of sensitive data. The issue poses a significant risk to employees who use remote desktop tools to access corporate resources or support systems.
Technical details
A heap-based buffer overflow exists in the Microsoft Remote Desktop Client. The vulnerability is triggered when a user connects to a malicious RDP server, which sends specially crafted responses that exceed allocated memory buffers. While the NVD description notes a heap overflow, the Microsoft CWE classification also mentions Use After Free (CWE-416) characteristics. An attacker can exploit this to achieve remote code execution (RCE) in the context of the logged-in user. User interaction is required as the victim must initiate a connection to the attacker-controlled server.
Affected products
- Microsoft Remote Desktop Client
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory: Published by Microsoft and NVD