Junglewise Threat Intelligence

CVE-2026-50330: Microsoft Remote Desktop Client heap overflow privilege escalation

CVE-2026-50330 · Severity: high · CVSS 7.5 · Published 2026-07-14

Technologies: Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Microsoft Remote Desktop Client, a tool used to connect to and control computers remotely. An unauthorized attacker could exploit this flaw over a network to gain higher-level system permissions than they should have. This could allow an attacker to bypass security restrictions or potentially disrupt operations on the affected device.

Technical details

A heap-based buffer overflow (CWE-122) exists in the Microsoft Remote Desktop Client. The vulnerability is reachable over the network and does not require prior authentication or user interaction. By sending specially crafted data to the client, an attacker can trigger the overflow to achieve elevation of privilege. The flaw affects multiple versions of Windows 10, Windows 11, and Windows Server 2012. Microsoft has released security updates to address this issue; users should apply the latest cumulative updates for their respective OS versions.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2012 All editions

Timeline

  • 2026-07-14: advisory: Initial advisory published by Microsoft and NVD.
  • 2026-07-14: patched: Security updates released by Microsoft.

References

Related threats