Junglewise Threat Intelligence

CVE-2026-54990: Microsoft Remote Desktop Client heap overflow remote code execution

CVE-2026-54990 · Severity: critical · CVSS 9.8 · Published 2026-07-14

Technologies: Microsoft Windows 11 Version 24H2, Microsoft Windows 11 Version 26H1, Microsoft Windows Server 2025, Microsoft Windows 11, Microsoft Windows 11 Version 25H2. Vendors: Microsoft.

Executive brief

A critical vulnerability has been identified in the Microsoft Remote Desktop Client, a tool used to connect to and control remote computers. An unauthorized attacker could exploit this flaw over a network to execute malicious code on a target system without any user interaction. This could lead to a complete takeover of the affected machine, potentially resulting in data theft, service disruption, or further lateral movement within a corporate network.

Technical details

A heap-based buffer overflow vulnerability (CWE-122) exists in the Microsoft Remote Desktop Client. The flaw is triggered when the client processes specially crafted network packets, allowing an unauthenticated attacker to achieve remote code execution (RCE) with the privileges of the user running the client. The attack vector is network-based and requires no prior authentication or user interaction (UI:N). Affected versions include various builds of Windows 11 and Windows Server 2025; users are advised to apply the latest security updates from Microsoft to mitigate this risk.

Affected products

  • Microsoft Windows 11 Version 24H2 10.0.26100.0 to 10.0.26100.8875
  • Microsoft Windows 11 Version 25H2 10.0.26200.0 to 10.0.26200.8875
  • Microsoft Windows 11 version 26H1 10.0.26200.0 to 10.0.28000.2269
  • Microsoft Windows Server 2025 10.0.26100.0 to 10.0.26100.33158

Timeline

  • 2026-07-14: disclosed
  • 2026-07-14: advisory

References

Related threats