Junglewise Threat Intelligence

CVE-2026-47654: Microsoft Remote Desktop Client heap overflow remote code execution

CVE-2026-47654 · Severity: high · CVSS 7.5 · Published 2026-06-09

Technologies: Microsoft Remote Desktop Client. Vendors: Microsoft.

Executive brief

Microsoft Remote Desktop Client, a tool used to connect to and control remote computers, contains a critical security flaw. An attacker could exploit this vulnerability to gain control over a user's computer if the user connects to a malicious server. This could lead to the theft of sensitive data, installation of malware, or complete system takeover.

Technical details

A heap-based buffer overflow vulnerability exists in the Microsoft Remote Desktop Client. The flaw is triggered when a client connects to a malicious or compromised Remote Desktop server. Although the attack vector is network-based and requires no prior privileges, it has high complexity and requires user interaction, as the victim must initiate a connection to the attacker-controlled server. Successful exploitation allows for remote code execution (RCE) in the context of the logged-on user. While the description mentions a buffer overflow, the associated CWE-416 suggests a potential use-after-free condition may also be involved in the memory corruption.

Affected products

  • Microsoft Remote Desktop Client

Timeline

  • 2026-06-09: disclosed: Initial publication by Microsoft and NVD

References

Related threats