Executive brief
A security vulnerability exists in the Microsoft Remote Desktop Client, a tool used by employees to access remote computers and servers. An attacker could exploit this flaw to take control of a user's computer if the user connects to a malicious server. This could lead to the theft of sensitive data, installation of malware, or a complete compromise of the affected workstation.
Technical details
A heap-based buffer overflow vulnerability exists in the Microsoft Remote Desktop Client. The flaw is triggered when a client connects to a malicious or compromised Remote Desktop Protocol (RDP) server. While the vulnerability is reachable over the network without prior authentication, successful exploitation requires user interaction, specifically the act of connecting to the attacker-controlled server. If successfully exploited, an attacker can achieve remote code execution (RCE) in the context of the logged-on user. Although the NVD description mentions a heap overflow, the Microsoft CWE classification also references CWE-416 (Use After Free), suggesting memory corruption during session handling.
Affected products
- Microsoft Remote Desktop Client
Timeline
- 2026-06-09: disclosed
- 2026-06-09: advisory