Executive brief
A security vulnerability exists in the Microsoft Remote Desktop Client, a tool used by employees to access computers and servers remotely. An attacker could exploit this flaw to take control of a user's computer if the user is tricked into connecting to a malicious server. This could lead to the theft of sensitive data, installation of malware, or a complete compromise of the affected workstation.
Technical details
A use-after-free vulnerability (CWE-416) exists in the Microsoft Remote Desktop Client. The flaw is triggered when a user connects to a malicious RDP server, allowing the attacker to execute arbitrary code in the context of the logged-on user. While the attack vector is network-based, it requires user interaction (UI:R), typically in the form of connecting to a compromised or attacker-controlled host. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server 2012. Microsoft has released security updates to address this issue.
Affected products
- Microsoft Windows 10 1607, 1809, 21H2, 22H2
- Microsoft Windows 11 24H2, 25H2, 26H1
- Microsoft Windows Server 2012 Standard, Server Core
Timeline
- 2026-07-14: disclosed: Initial disclosure by Microsoft and NVD publication.
- 2026-07-14: patched: Security updates made available via Microsoft Update Guide.