Junglewise Threat Intelligence

CVE-2026-50474: Microsoft Remote Desktop Client use after free code execution

CVE-2026-50474 · Severity: high · CVSS 8.8 · Published 2026-07-14

Technologies: Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A security vulnerability exists in the Microsoft Remote Desktop Client, a tool used by employees to access computers and servers remotely. An attacker could exploit this flaw to take control of a user's computer if the user is tricked into connecting to a malicious server. This could lead to the theft of sensitive data, installation of malware, or a complete compromise of the affected workstation.

Technical details

A use-after-free vulnerability (CWE-416) exists in the Microsoft Remote Desktop Client. The flaw is triggered when a user connects to a malicious RDP server, allowing the attacker to execute arbitrary code in the context of the logged-on user. While the attack vector is network-based, it requires user interaction (UI:R), typically in the form of connecting to a compromised or attacker-controlled host. The vulnerability affects multiple versions of Windows 10, Windows 11, and Windows Server 2012. Microsoft has released security updates to address this issue.

Affected products

  • Microsoft Windows 10 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 24H2, 25H2, 26H1
  • Microsoft Windows Server 2012 Standard, Server Core

Timeline

  • 2026-07-14: disclosed: Initial disclosure by Microsoft and NVD publication.
  • 2026-07-14: patched: Security updates made available via Microsoft Update Guide.

References

Related threats