Junglewise Threat Intelligence

CVE-2026-69317: Microsoft Remote Desktop Client out-of-bounds read

CVE-2026-69317 · Severity: medium · CVSS 5.7 · Published 2026-09-08

Technologies: Microsoft Remote Desktop Client. Vendors: Microsoft.

Executive brief

Microsoft Remote Desktop Client is a tool that allows users to connect to and control remote computers over a network. An authorized attacker could exploit an out-of-bounds read vulnerability to access sensitive information from the affected system's memory, potentially exposing credentials, encryption keys, or other confidential data.

Technical details

The vulnerability is an out-of-bounds read in Microsoft Remote Desktop Client that allows an authorized attacker to disclose information over the network. The attack requires authentication (as indicated by "authorized attacker") and network connectivity to an affected system running the vulnerable client. Exploitation could enable memory disclosure attacks to extract sensitive data. Microsoft has addressed this vulnerability; patches are available via the Security Update Guide.

Affected products

  • Microsoft Remote Desktop Client

Timeline

  • 2026-09-08: disclosed

References

Related threats