Junglewise Threat Intelligence

CVE-2026-58594: Microsoft Windows RDP integer overflow remote code execution

CVE-2026-58594 · Severity: high · CVSS 8.8 · Published 2026-07-14

Technologies: Microsoft Windows Server 2012, Microsoft Windows 10, Microsoft Windows 11. Vendors: Microsoft.

Executive brief

A critical vulnerability has been identified in the Windows Remote Desktop Protocol (RDP), a tool commonly used for remote access to computers and servers. An attacker could exploit this flaw to remotely execute malicious code on a target system, potentially leading to a full system takeover or data theft. While the attack can be initiated over a network, it requires a user to perform an action, such as clicking a malicious link or connecting to a compromised server.

Technical details

This vulnerability is classified as an integer overflow or wraparound (CWE-190) within the Windows Remote Desktop Protocol (RDP) implementation. The flaw allows an unauthenticated attacker to achieve remote code execution (RCE) by sending specially crafted data over the network. Although the attack vector is network-based, the CVSS vector indicates that user interaction (UI:R) is required, suggesting the victim may need to connect to a malicious RDP server or trigger the exploit through a specific client-side action. Microsoft has released security updates to address this issue across multiple versions of Windows 10, Windows 11, and Windows Server 2012.

Affected products

  • Microsoft Windows 10 Version 1607, 1809, 21H2, 22H2
  • Microsoft Windows 11 Version 24H2, 25H2, 26H1
  • Microsoft Windows Server 2012 Standard and Server Core installations

Timeline

  • 2026-07-14: disclosed: Initial publication of the CVE record by Microsoft.
  • 2026-07-14: advisory: NVD entry published.

References

Related threats